José D'Abruzzo Pereira

dblp:259/0580 · DBLP profile ↗
← Back
3ranked-venue papers
2as first author
3since 2021 · last 2026
0000-0003-0717-3396ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 2 first-author · 3 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Leveraging Large Language Models for Trustworthiness Assessment of Web Applications
Oleksandr Yarotskyi, José D'Abruzzo Pereira, João R. Campos
ICST2
2023 An Approach to Characterize the Security of Open-Source Functions using LSP
abstract
The malicious exploitation of security flaws by attackers can lead to a range of problems. While several techniques and tools allow detecting vulnerabilities during the Software Development Life Cycle (SDLC), most face the challenge of generating many false alarms while failing to detect vulnerabilities. This leads software development teams to waste considerable time in the analysis and to deploy potentially vulnerable code. In this context, we believe that complementary solutions are needed to help teams focusing the vulnerability detection and refactoring efforts on the code units that are more prone to have security issues. In this paper, we propose SCOLP (Security Characterization of Open-Source Functions using Logic Scoring of Preference (LSP)), an approach based on Multi-Criteria Decision Making (MCDM), aimed at categorizing code units (functions) based on the perceived proneness to have security issues. In practice, we use static information (e.g., Software Metrics (SMs) and memory management-related attributes) collected from the source code to feed Quality Models (QMs) that output a score that is then used to categorize the code units. To demonstrate SCOLP, we developed several QMs and applied them to the functions of a large open-source project developed using the C language (Linux Kernel). A preliminary validation with security experts was conducted to assess the accuracy of the categorization. Despite the subjectiveness of the process, results show that the output of SCOLP is aligned with the view of security experts. Our technique can be easily integrated into the SDLC without adding overhead to the development processes.
José D'Abruzzo Pereira, Marco Vieira
ISSRE1
2022 A Software Vulnerability Dataset of Large Open Source C/C++ Projects
abstract
Automated tools, namely Static Analysis Tools (SATs) and Penetration Testing Tools, are frequently used by developers to detect vulnerabilities. However, research and practice show that the effectiveness of those tools in large-scale projects is low, being prone to both false positives and false negatives. Thus, there is an urgent need for more effective techniques, which ultimately require representative field data for driving their design and testing. In this paper, we present a dataset of vulnerabilities from five large open-source C/C++ projects: Mozilla, Linux Kernel, Xen, httpd, and Glibc. For collecting the data, we designed an automated process grounded on vulnerabilities collected from the Common Vulnerability and Exposures (CVE) Details website. For each vulnerability, we retrieve the corresponding source code units from the project repository (including both vulnerable and fixed versions). We then compute a large set of Software Metrics (SMs) for those code units and run two SATs to collect security alerts (i.e., potential vulnerabilities and/or weaknesses). The dataset currently includes 5214 vulnerabilities. To demonstrate its usefulness, we explore the use of the dataset to train machine learning models to detect vulnerable C/C++ functions. Results clearly show that the dataset can be used in practice and is a key contribution for researchers working in software security.
José D'Abruzzo Pereira, João Henggeler Antunes, Marco Vieira
PRDC1