VLDB 2026 Research / reviewers in the wild / expert
Paul E. Black
dblp:16/6383
· DBLP profile ↗
13ranked-venue papers
4as first author
0since 2021 · last 2019
0000-0002-7561-6614ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 12 · 4 first-authorApplied, interdisciplinary, general and emerging computing · 3Theory of computation · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
1 paper |
Systems and software security · 100% | |
| Software engineering, system software, and programming languages
2 papers |
Software testing · 100% | |
| Computer networks
1 paper |
Network performance modeling · 100% |
Topics — the 8 heaviest of 9, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
vulnerability discovery |
0.1 | 1 | 2005 | Software security assurance tools, techniques and metrics (SSATTM) · ASE 2005 |
Systems and software security › vulnerability analysis
vulnerability taxonomy |
0.1 | 1 | 2005 | Software security assurance tools, techniques and metrics (SSATTM) · ASE 2005 |
Software testing
mutation testing |
0.0 | 1 | 2000 | Mutation Operators for Specifications · ASE 2000 |
Software testing › test generation
specification-based test generation |
0.0 | 1 | 2000 | Mutation Operators for Specifications · ASE 2000 |
Software testing › test generation
test suite generation |
0.0 | 1 | 2000 | Mutation Operators for Specifications · ASE 2000 |
Software testing › non-functional testing
security testing |
0.0 | 1 | 2005 | Software security assurance tools, techniques and metrics (SSATTM) · ASE 2005 |
Network performance modeling
queueing analysis |
0.0 | 1 | 1994 | Queueing Analysis of Oblivious Packet-Routing Networks · SODA 1994 |
Software testing
fault detection |
0.0 | 1 | 2000 | Mutation Operators for Specifications · ASE 2000 |
Methods — techniques the papers use, named apart from their topics
mutation analysis · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2019 | Information Exposure (IEX): A New Class in the Bugs Framework (BF)abstractExposure of sensitive information can be harmful on its own. In addition, it could enable further attacks. A rigorous and unambiguous definition of information exposure faults can help researchers and practitioners identify them, thus avoiding security failures. This paper describes Information Exposure (IEX), a new class in the Bugs Framework (BF). The IEX class comprises a rigorous definition and (static) attributes of the class, along with their related dynamic properties, such as proximate and secondary causes, consequences and sites. We use the IEX class to analyze specific vulnerabilities and provide clear descriptions. We also discuss lessons we learned that will help create additional BF classes. Irena Bojanova, Yaacov Yesha, Paul E. Black |
COMPSAC (1) | 3 |
| 2019 | Classification of Smart Contract Bugs Using the NIST Bugs FrameworkabstractBlockchain technology has recently emerged as the primary platform for the transfer of digital currency. This technology, which has been heralded as a revolutionary tool to facilitate the transfer of funds between participating parties, is still in its infancy and should be subjected to thorough scrutiny. In recent years, researchers have attempted to uncover a litany of bugs embedded within these distributed systems; however, there does not yet exist a formal and standardized method for their classification. In this paper, we present the first formal classifications of known bugs in smart contract systems using NIST's Bugs Framework and propose two new classes: Distributed System Protocol (DSP) and Distributed System Resource Management (DRM). Wesley Dingman, Aviel Cohen, Nick Ferrara, Adam Lynch, Patrick Jasinski, Paul E. Black, Lin Deng 0001 |
SERA | 6 |
| 2019 | TOOLympics 2019: An Overview of Competitions in Formal MethodsabstractEvaluation of scientific contributions can be done in many different ways. For the various research communities working on the verification of systems (software, hardware, or the underlying involved mechanisms), it is important to bring together the community and to compare the state of the art, in order to identify progress of and new challenges in the research area. Competitions are a suitable way to do that. The first verification competition was created in 1992 (SAT competition), shortly followed by the CASC competition in 1996. Since the year 2000, the number of dedicated verification competitions is steadily increasing. Many of these events now happen regularly, gathering researchers that would like to understand how well their research prototypes work in practice. Scientific results have to be reproducible, and powerful computers are becoming cheaper and cheaper, thus, these competitions are becoming an important means for advancing research in verification technology. TOOLympics 2019 is an event to celebrate the achievements of the various competitions, and to understand their commonalities and differences. This volume is dedicated to the presentation of the 16 competitions that joined TOOLympics as part of the celebration of the $$25^{ th }$$ anniversary of the TACAS conference. Ezio Bartocci, Dirk Beyer 0001, Paul E. Black, Grigory Fedyukovich, Hubert Garavel, Arnd Hartmanns, Marieke Huisman, Fabrice Kordon, Julian Nagele, Mihaela Sighireanu, Bernhard Steffen, Martin Suda 0001, Geoff Sutcliffe, Tjark Weber, Akihisa Yamada 0002 |
TACAS (3) | 3 |
| 2018 | Randomness Classes in Bugs Framework (BF): True-Random Number Bugs (TRN) and Pseudo-Random Number Bugs (PRN)abstractRandom number generators may have weaknesses (bugs) and the applications using them may become vulnerable to attacks. Formalization of randomness bugs would help researchers and practitioners identify them and avoid security failures. The Bugs Framework (BF) comprises rigorous definitions and (static) attributes of bug classes, along with their related dynamic properties, such as proximate and secondary causes, consequences and sites. This paper presents two new BF classes: True-Random Number Bugs (TRN) and Pseudo-Random Number Bugs (PRN). We analyze particular vulnerabilities and use these classes to provide clear BF descriptions. Finally, we discuss the lessons learned towards creating new BF class. Irena Bojanova, Yaacov Yesha, Paul E. Black |
COMPSAC (1) | 3 |
| 2016 | The Bugs Framework (BF): A Structured Approach to Express BugsabstractTo achieve higher levels of assurance for digital systems, we need to answer questions such as does this software have bugs of these critical classes? Do two software assurance tools find the same set of bugs or different, complimentary sets? Can we guarantee that a new technique discovers all problems of this type? To answer such questions, we need a vastly improved way to describe classes of vulnerabilities and chains of failures. We present the Bugs Framework (BF), which raises the current realm of best efforts and useful heuristics. Our BF includes rigorous definitions and (static) attributes of bug classes, along with their related dynamic properties, such as proximate, secondary and tertiary causes, consequences and sites. The paper discusses the buffer overflow class, the injection class and the control of interaction frequency class, and provides examples of applying our BF taxonomy to describe particular vulnerabilities. Irena Bojanova, Paul E. Black, Yaacov Yesha |
QRS | 2 |
| 2011 | Counting Bugs is Harder Than You ThinkabstractSoftware Assurance Metrics and Tool Evaluation (SAMATE) is a broad, inclusive project at the U.S. National Institute of Standards and Technology (NIST) with the goal of improving software assurance by developing materials, specifications, and methods to test tools and techniques and measure their effectiveness. We review some SAMATE sub-projects: web application security scanners, malware research protocol, electronic voting systems, the SAMATE Reference Dataset, a public repository of thousands of example programs with known weaknesses, and the Static Analysis Tool Exposition (SATE). Along the way we list over two dozen possible research questions, which are also collaboration opportunities. Software metrics are incomplete without metrics of what is variously called bugs, flaws, or faults. We detail numerous critical research problems related to such metrics. For instance, is a warning from a source code scanner a real bug, a false positive, or something else? If a numeric overflow leads to buffer overflow, which leads to command injection, what is the error? How many bugs are there if two sources call two sinks: 1, 2, or 4? Where is a missing feature? We conclude with a list of concepts which may be a useful basis of bug metrics. Paul E. Black |
SCAM | 1 |
| 2006 | Software Assurance During MaintenanceabstractSoftware development, testing, and maintenance tools must yield assurance information in a standardized form. Developers can use this information to argue that the software is adequate for its use and secure enough for the risk. NIST's Software Assurance Metrics And Tool Evaluation (SAMATE) project is developing specifications for software assurance tools. These specifications can include optional features for assurance information reports, encouraging tools to provide them. During maintenance, developers can collect this information to make explicit assurance cases Paul E. Black |
ICSM | 1 |
| 2005 | Software security assurance tools, techniques and metrics (SSATTM)abstractThe purpose of the workshop is to convene researchers, developers, and government and industrial users of software security assurance (SSA) tools to refine the taxonomy of flaws and the taxonomy of SSA tool functions, converge on which SSA functions should first have specifications and tests developed, gather SSA tool developers for "target practice" on the reference datasets, and identify gaps or requirements for research in SSA functions. There are contributions describing basic research, novel applications, and experience relevant to SSA tools and their evaluation. The reference datasets are code with known flaws and vulnerabilities, with corresponding correct versions, to be used as references for tool testing, to make research easier, and to be a standard of evaluation. Tools ranging from commercial products to university projects "shoot holes" in the datasets to suggest extensions, improvements, etc. This is a U.S. National Institute of Standards and Technology SAMATE (http://samate.nist.gov/) workshop. Paul E. Black, Michael Kass |
ASE | 1 |
| 2004 | Comparison of fault classes in specification-based testing
Vadim Okun, Paul E. Black, Yaacov Yesha |
Inf. Softw. Technol. | 2 |
| 2000 | Mutation Operators for SpecificationsabstractTesting has a vital support role in the software engineering process, but developing tests often takes significant resources. A formal specification is a repository of knowledge about a system, and a recent method uses such specifications to automatically generate complete test suites via mutation analysis. We define an extensive set of mutation operators for use with this method. We report the results of our theoretical and experimental investigation of the relationships between the classes of faults detected by the various operators. Finally, we recommend sets of mutation operators which yield good test coverage at a reduced cost compared to using all proposed operators. Paul E. Black, Vadim Okun, Yaacov Yesha |
ASE | 1 |
| 1998 | Reliability of Conformance TestsabstractA conformance test is a software assurance test that is applied in order to determine if specification requirements of the software are being met. It is a time-independent model, where the software object is subjected to an a priori known test suite. The reliability of the software is the probability that it will function properly for values in the input space. Because the input space is usually very large, it is impossible to sample all input values, so in order to provide better sampling coverage, the input space is partitioned into homogeneous subspaces. Samples are drawn from each subspace for testing the software. The conformance tests based on these samples are required to pass all tests in the test suite. Based on these data, the classical statistical estimate of reliability is one. Such an estimate may be unrealistic if the sample sizes are not large. Even in such a scenario a nontrivial confidence interval is provided for the reliability. Charles Hagwood, Raghu Kacker, James Yen, David Banks, Lynne Rosenthal, Leonard Gallagher, Paul E. Black |
COMPSAC | 7 |
| 1998 | Using Model Checking to Generate Tests from SpecificationsabstractWe apply a model checker to the problem of test generation using a new application of mutation analysis. We define syntactic operators, each of which produces a slight variation on a given model. The operators define a form of mutation analysis at the level of the model checker specification. A model checker generates countersamples which distinguish the variations from the original specification. The countersamples can easily be turned into complete test cases, that is, with inputs and expected results. We define two classes of operators: those that produce test cases from which a correct implementation must differ, and those that produce test cases with which it must agree. There are substantial advantages to combining a model checker with mutation analysis. First, test case generation is automatic; each countersample is a complete test case. Second, in sharp contrast to program-based mutation analysis, equivalent mutant identification is also automatic. We apply our method to an example specification and evaluate the resulting test sets with coverage metrics on a Java implementation. Paul Ammann, Paul E. Black, William Majurski |
ICFEM | 2 |
| 1994 | Queueing Analysis of Oblivious Packet-Routing Networks
Mor Harchol-Balter, Paul E. Black |
SODA | 2 |