Duy Cu Nguyen

dblp:34/2299 · also Cu D. Nguyen, Cu Duy Nguyen · DBLP profile ↗
← Back
24ranked-venue papers
6as first author
3since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 17 · 5 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Security and privacy · 2 · 1 since 2021Computer networks · 1Applied, interdisciplinary, general and emerging computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
9 papers
Software testing · 77% Debugging and program repair · 14% Empirical software engineering · 9%
Network and information security
3 papers
Systems and software security · 71% Web and mobile security · 29%

Topics — the 14 heaviest of 19, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Software testing
test generation
0.742015
Do Automatically Generated Test Cases Make Debugging Easier? An Experimental Assessment of Debugging Effectiveness and Efficiency · ACM Trans. Softw. Eng. Methodol. 2015
Interpolated n-grams for model based testing · ICSE 2014
Combining model-based and combinatorial testing for effective test case generation · ISSTA 2012
Software testing › non-functional testing
security testing
0.422016
SOFIA: an automated security oracle for black-box testing of SQL-injection vulnerabilities · ASE 2016
Automated testing for SQL injection vulnerabilities: an input mutation approach · ISSTA 2014
Software testing
test oracle
0.422016
SOFIA: an automated security oracle for black-box testing of SQL-injection vulnerabilities · ASE 2016
Automated oracles: an empirical study on cost and effectiveness · ESEC/SIGSOFT FSE 2013
Debugging and program repair
debugging effectiveness
0.422015
Do Automatically Generated Test Cases Make Debugging Easier? An Experimental Assessment of Debugging Effectiveness and Efficiency · ACM Trans. Softw. Eng. Methodol. 2015
An empirical study about the effectiveness of debugging when random test cases are used · ICSE 2012
Software testing › test generation
automated test generation
0.212016
Automated and effective testing of web services for XML injection attacks · ISSTA 2016
Software testing › test generation
mutation-based test generation
0.212016
Automated and effective testing of web services for XML injection attacks · ISSTA 2016
Empirical software engineering
developer studies
0.212015
Do Automatically Generated Test Cases Make Debugging Easier? An Experimental Assessment of Debugging Effectiveness and Efficiency · ACM Trans. Softw. Eng. Methodol. 2015
Software testing
combinatorial testing
0.222013
Automated inference of classifications and dependencies for combinatorial testing · ASE 2013
Combining model-based and combinatorial testing for effective test case generation · ISSTA 2012
Software testing
model-based testing
0.212014
Interpolated n-grams for model based testing · ICSE 2014
Software testing › test oracle
oracle automation
0.212013
Automated oracles: an empirical study on cost and effectiveness · ESEC/SIGSOFT FSE 2013
Debugging and program repair
fault localization
0.112012
An empirical study about the effectiveness of debugging when random test cases are used · ICSE 2012
Systems and software security
vulnerability discovery
0.112016
SOFIA: an automated security oracle for black-box testing of SQL-injection vulnerabilities · ASE 2016
Web and mobile security › web application security
web services security
0.112016
Automated and effective testing of web services for XML injection attacks · ISSTA 2016
Empirical software engineering
controlled experiment
0.012012
An empirical study about the effectiveness of debugging when random test cases are used · ICSE 2012

Methods — techniques the papers use, named apart from their topics

fuzzing · 0.5constraint solving · 0.5black-box testing · 0.5mutation operators · 0.4controlled experiment · 0.4replication · 0.2interpolated n-grams · 0.2finite-state machine model · 0.2machine learning · 0.2clustering · 0.2
YearPublicationVenuePosition
2026 Developing Intelligent Chatbots for Telecom Security Support: A Comparative Study of Large Language Model Utilization Strategies
Yuejun Guo 0001, Qiang Tang 0001, Duy Cu Nguyen
ICAART (3)4
2022 A CNN-Based Semi-supervised Learning Approach for the Detection of SS7 Attacks
Orhan Ermis, Christophe Feltus, Qiang Tang 0001, Alexandre De Oliveira, Duy Cu Nguyen, Alain Hirtzig
ISPEC6
2022 Automated reverse engineering of role-based access control policies of web applications
Lwin Khin Shar, Domenico Bianculli, Lionel C. Briand, Duy Cu Nguyen
J. Syst. Softw.5
2019 An Experimental Analysis of Fraud Detection Methods in Enterprise Telecommunication Data using Unsupervised Outlier Ensembles
Georgios Kaiafas, Christian A. Hammerschmidt, Radu State, Duy Cu Nguyen, Thorsten Ries, Mohamed Ourdane
IM4
2018 Detecting malicious authentication events trustfully
abstract
Anomaly detection on security logs is receiving more and more attention. Authentication events are an important component of security logs, and being able to produce trustful and accurate predictions minimizes the effort of cyber-experts to stop false attacks. Observed events are classified into Normal, for legitimate user behavior, and Malicious, for malevolent actions. These classes are consistently excessively imbalanced which makes the classification problem harder; in the commonly used Los Alamos dataset, the malicious class comprises only 0.00033% of the total. This work proposes a novel method to extract advanced composite features, and a supervised learning technique for classifying authentication logs trustfully; the models are Random Forest, LogitBoost, Logistic Regression, and ultimately Majority Voting which leverages the predictions of the previous models and gives the final prediction for each authentication event. We measure the performance of our experiments by using the False Negative Rate and False Positive Rate. In overall we achieve 0 False Negative Rate (i.e. no attack was missed), and on average a False Positive Rate of 0.0019.
Georgios Kaiafas, Georgios Varisteas, Sofiane Lagraa, Radu State, Duy Cu Nguyen, Thorsten Ries, Mohamed Ourdane
NOMS5
2018 A Machine-Learning-Driven Evolutionary Approach for Testing Web Application Firewalls
abstract
Web application firewalls (WAFs) are an essential protection mechanism for online software systems. Because of the relentless flow of new kinds of attacks as well as their increased sophistication, WAFs have to be updated and tested regularly to prevent attackers from easily circumventing them. In this paper, we focus on testing WAFs for SQL injection attacks, but the general principles and strategy we propose can be adapted to other contexts. We present ML-Driven, an approach based on machine learning and an evolutionary algorithm to automatically detect holes in WAFs that let SQL injection attacks bypass them. Initially, ML-Driven automatically generates a diverse set of attacks and submits them to the system being protected by the target WAF. Then, ML-Driven selects attacks that exhibit patterns (substrings) associated with bypassing the WAF and evolves them to generate new successful bypassing attacks. Machine learning is used to incrementally learn attack patterns from previously generated attacks according to their testing results, i.e., if they are blocked or bypass the WAF. We implemented ML-Driven in a tool and evaluated it on ModSecurity, a widely used open-source WAF, and a proprietary WAF protecting a financial institution. Our empirical results indicate that ML-Driven is effective and efficient at generating SQL injection attacks bypassing WAFs and identifying attack patterns.
Dennis Appelt, Duy Cu Nguyen, Annibale Panichella, Lionel C. Briand
IEEE Trans. Reliab.2
2017 A Search-Based Testing Approach for XML Injection Vulnerabilities in Web Applications
abstract
In most cases, web applications communicate with web services (SOAP and RESTful). The former act as a front-end to the latter, which contain the business logic. A hacker might not have direct access to those web services (e.g., they are not on public networks), but can still provide malicious inputs to the web application, thus potentially compromising related services. Typical examples are XML injection attacks that target SOAP communications. In this paper, we present a novel, search-based approach used to generate test data for a web application in an attempt to deliver malicious XML messages to web services. Our goal is thus to detect XML injection vulnerabilities in web applications. The proposed approach is evaluated on two studies, including an industrial web application with millions of users. Results show that we are able to effectively generate test data (e.g., input values in an HTML form) that detect such vulnerabilities.
Sadeeq Jan, Duy Cu Nguyen, Andrea Arcuri, Lionel C. Briand
ICST2
2016 Automated and effective testing of web services for XML injection attacks
abstract
XML is extensively used in web services for integration and data exchange. Its popularity and wide adoption make it an attractive target for attackers and a number of XML-based attack types have been reported recently. This raises the need for cost-effective, automated testing of web services to detect XML-related vulnerabilities, which is the focus of this paper. We discuss a taxonomy of the types of XML injection attacks and use it to derive four different ways to mutate XML messages, turning them into attacks (tests) automatically. Further, we consider domain constraints and attack grammars, and use a constraint solver to generate XML messages that are both malicious and valid, thus making it more difficult for any protection mechanism to recognise them. As a result, such messages have a better chance to detect vulnerabilities. Our evaluation on an industrial case study has shown that a large proportion (78.86%) of the attacks generated using our approach could circumvent the first layer of security protection, an XML gateway (firewall), a result that is much better than what a state-of-the-art tool based on fuzz testing could achieve.
Sadeeq Jan, Duy Cu Nguyen, Lionel C. Briand
ISSTA2
2016 SOFIA: an automated security oracle for black-box testing of SQL-injection vulnerabilities
abstract
Security testing is a pivotal activity in engineering secure software. It consists of two phases: generating attack inputs to test the system, and assessing whether test executions expose any vulnerabilities. The latter phase is known as the security oracle problem.
Mariano Ceccato, Duy Cu Nguyen, Dennis Appelt, Lionel C. Briand
ASE2
2015 Behind an Application Firewall, Are We Safe from SQL Injection Attacks?
abstract
Web application firewalls are an indispensable layer to protect online systems from attacks. However, the fast pace at which new kinds of attacks appear and their sophistication require that firewalls be updated and tested regularly as otherwise they will be circumvented. In this paper, we focus our research on web application firewalls and SQL injection attacks. We present a machine learning-based testing approach to detect holes in firewalls that let SQL injection attacks bypass. At the beginning, the approach can automatically generate diverse attack payloads, which can be seeded into inputs of web- based applications, and then submit them to a system that is protected by a firewall. Incrementally learning from the tests that are blocked or passed by the firewall, our approach can then select tests that exhibit characteristics associated with bypassing the firewall and mutate them to efficiently generate new bypassing attacks. In the race against cyber attacks, time is vital. Being able to learn and anticipate more attacks that can circumvent a firewall in a timely manner is very important in order to quickly fix or fine-tune the firewall. We developed a tool that implements the approach and evaluated it on ModSecurity, a widely used application firewall. The results we obtained suggest a good performance and efficiency in detecting holes in the firewall that could let SQLi attacks go undetected.
Dennis Appelt, Duy Cu Nguyen, Lionel C. Briand
ICST2
2015 Known XML Vulnerabilities Are Still a Threat to Popular Parsers and Open Source Systems
abstract
The Extensible Markup Language (XML) is extensively used in software systems and services. Various XML-based attacks, which may result in sensitive information leakage or denial of services, have been discovered and published. However, due to development time pressures and limited security expertise, such attacks are often overlooked in practice. In this paper, following a rigorous and extensive experimental process, we study the presence of two types of XML-based attacks: BIL and XXE in 13 popular XML parsers. Furthermore, we investigate whether open-source systems that adopt a vulnerable XML parser apply any mitigation to prevent such attacks. Our objective is to provide clear and solid scientific evidence about the extent of the threat associated with such XML-based attacks and to discuss the implications of the obtained results. Our conclusion is that most of the studied parsers are vulnerable and so are systems that use them. Such strong evidence can be used to raise awareness among software developers and is a strong motivation for developers to provide security measures to thwart BIL and XXE attacks before deployment when adopting existing XML parsers.
Sadeeq Jan, Duy Cu Nguyen, Lionel C. Briand
QRS2
2015 Automated Inference of Access Control Policies for Web Applications
abstract
In this paper, we present a novel, semi-automated approach to infer access control policies automatically for web-based applications. Our goal is to support the validation of implemented access control policies, even when they have not been clearly specified or documented. We use role-based access control as a reference model. Built on top of a suite of security tools, our approach automatically exercises a system under test and builds access spaces for a set of known users and roles. Then, we apply a machine learning technique to infer access rules. Inconsistent rules are then analysed and fed back to the process for further testing and improvement. Finally, the inferred rules can be validated based on pre-specified rules if they exist. Otherwise, the inferred rules are presented to human experts for validation and for detecting access control issues. We have evaluated our approach on two applications; one is open source while the other is a proprietary system built by our industry partner. The obtained results are very promising in terms of the quality of inferred rules and the access control vulnerabilities it helped detect.
Ha-Thanh Le, Duy Cu Nguyen, Lionel C. Briand, Benjamin Hourte
SACMAT2
2015 Do Automatically Generated Test Cases Make Debugging Easier? An Experimental Assessment of Debugging Effectiveness and Efficiency
abstract
Several techniques and tools have been proposed for the automatic generation of test cases. Usually, these tools are evaluated in terms of fault-revealing or coverage capability, but their impact on the manual debugging activity is not considered. The question is whether automatically generated test cases are equally effective in supporting debugging as manually written tests. We conducted a family of three experiments (five replications) with humans (in total, 55 subjects) to assess whether the features of automatically generated test cases, which make them less readable and understandable (e.g., unclear test scenarios, meaningless identifiers), have an impact on the effectiveness and efficiency of debugging. The first two experiments compare different test case generation tools (Randoop vs. EvoSuite). The third experiment investigates the role of code identifiers in test cases (obfuscated vs. original identifiers), since a major difference between manual and automatically generated test cases is that the latter contain meaningless (obfuscated) identifiers. We show that automatically generated test cases are as useful for debugging as manual test cases. Furthermore, we find that, for less experienced developers, automatic tests are more useful on average due to their lower static and dynamic complexity.
Mariano Ceccato, Alessandro Marchetto 0001, Leonardo Mariani, Duy Cu Nguyen, Paolo Tonella
ACM Trans. Softw. Eng. Methodol.4
2014 Interpolated n-grams for model based testing
abstract
Models - in particular finite state machine models - provide an invaluable source of information for the derivation of effective test cases. However, models usually approximate part of the program semantics and capture only some of the relevant dependencies and constraints. As a consequence, some of the test cases that are derived from models are infeasible.
Paolo Tonella, Roberto Tiella, Duy Cu Nguyen
ICSE3
2014 Automated testing for SQL injection vulnerabilities: an input mutation approach
abstract
Web services are increasingly adopted in various domains, from finance and e-government to social media. As they are built on top of the web technologies, they suffer also an unprecedented amount of attacks and exploitations like the Web. Among the attacks, those that target SQL injection vulnerabilities have consistently been top-ranked for the last years. Testing to detect such vulnerabilities before making web services public is crucial. We present in this paper an automated testing approach, namely μ4SQLi, and its underpinning set of mutation operators. μ4SQLi can produce effective inputs that lead to executable and harmful SQL statements. Executability is key as otherwise no injection vulnerability can be exploited. Our evaluation demonstrated that the approach is effective to detect SQL injection vulnerabilities and to produce inputs that bypass application firewalls, which is a common configuration in real world.
Dennis Appelt, Duy Cu Nguyen, Lionel C. Briand, Nadia Alshahwan
ISSTA2
2013 Evaluating the FITTEST Automated Testing Tools: An Industrial Case Study
abstract
This paper aims at evaluating a set of automated tools of the FITTEST EU project within an industrial case study. The case study was conducted at the IBM Research lab in Haifa, by a team responsible for building the testing environment for future development versions of an IBM system management product. The main function of that product is resource management in a networked environment. This case study has investigated whether current IBM Research testing practices could be improved or complemented by using some of the automated testing tools that were developed within the FITTEST EU project. Although the existing Test Suite from IBM Research (TSibm) that was selected for comparison is substantially smaller than the Test Suite generated by FITTEST (TSfittest), the effectiveness of TSfittest, measured by the injected faults coverage is significantly higher (50% vs 70%). With respect to efficiency, by normalizing the execution times, we found the TSfittest runs faster (9.18 vs. 6.99). This is due to the fact that the TSfittest includes shorter tests. Within IBM Research and for the testing of the target product in the simulated environment: the FITTEST tools can increase the effectiveness of the current practice and the test cases automatically generated by the FITTEST tools can help in more efficient identification of the source of the identified faults. Moreover, the FITTEST tools have shown the ability to automate testing within a real industry case.
Duy Cu Nguyen, Bilha Mendelson, Daniel Citron, Onn Shehory, Tanja E. J. Vos, Nelly Condori-Fernández
ESEM1
2013 Automated inference of classifications and dependencies for combinatorial testing
abstract
Even for small programs, the input space is huge - often unbounded. Partition testing divides the input space into disjoint equivalence classes and combinatorial testing selects a subset of all possible input class combinations, according to criteria such as pairwise coverage. The down side of this approach is that the partitioning of the input space into equivalence classes (input classification) is done manually. It is expensive and requires deep domain and implementation understanding. In this paper, we propose a novel approach to classify test inputs and their dependencies automatically. Firstly, random (or automatically generated) input vectors are sent to the system under test (SUT). For each input vector, an observed “hit vector” is produced by monitoring the execution of the SUT. Secondly, hit vectors are grouped into clusters using machine learning. Each cluster contains similar hit vectors, i.e., similar behaviors, and from them we obtain corresponding clusters of input vectors. Input classes are then extracted for each input parameter straightforwardly. Our experiments with a number of subjects show good results as the automatically generated classifications are the same or very close to the expected ones.
Duy Cu Nguyen, Paolo Tonella
ASE1
2013 Automated oracles: an empirical study on cost and effectiveness
abstract
Software testing is an effective, yet expensive, method to improve software quality. Test automation, a potential way to reduce testing cost, has received enormous research attention recently, but the so-called “oracle problem” (how to decide the PASS/FAIL outcome of a test execution) is still a major obstacle to such cost reduction. We have extensively investigated state-of-the-art works that contribute to address this problem, from areas such as specification mining and model inference. In this paper, we compare three types of automated oracles: Data invariants, Temporal invariants, and Finite State Automata. More specifically, we study the training cost and the false positive rate; we evaluate also their fault detection capability. Seven medium to large, industrial application subjects and real faults have been used in our empirical investigation.
Duy Cu Nguyen, Alessandro Marchetto 0001, Paolo Tonella
ESEC/SIGSOFT FSE1
2012 An empirical study about the effectiveness of debugging when random test cases are used
abstract
Automatically generated test cases are usually evaluated in terms of their fault revealing or coverage capability. Beside these two aspects, test cases are also the major source of information for fault localization and fixing. The impact of automatically generated test cases on the debugging activity, compared to the use of manually written test cases, has never been studied before. In this paper we report the results obtained from two controlled experiments with human subjects performing debugging tasks using automatically generated or manually written test cases. We investigate whether the features of the former type of test cases, which make them less readable and understandable (e.g., unclear test scenarios, meaningless identifiers), have an impact on accuracy and efficiency of debugging. The empirical study is aimed at investigating whether, despite the lack of readability in automatically generated test cases, subjects can still take advantage of them during debugging.
Mariano Ceccato, Alessandro Marchetto 0001, Leonardo Mariani, Duy Cu Nguyen, Paolo Tonella
ICSE4
2012 Finding the Optimal Balance between Over and Under Approximation of Models Inferred from Execution Logs
abstract
Models inferred from execution traces (logs) may admit more behaviours than those possible in the real system (over-approximation) or may exclude behaviours that can indeed occur in the real system (under-approximation). Both problems negatively affect model based testing. In fact, over-approximation results in infeasible test cases, i.e., test cases that cannot be activated by any input data. Under-approximation results in missing test cases, i.e., system behaviours that are not represented in the model are also never tested. In this paper we balance over- and under-approximation of inferred models by resorting to multi-objective optimization achieved by means of two search-based algorithms: A multi-objective Genetic Algorithm (GA) and the NSGA-II. We report the results on two open-source web applications and compare the multi-objective optimization to the state-of-the-art KLFA tool. We show that it is possible to identify regions in the Pareto front that contain models which violate fewer application constraints and have a higher bug detection ratio. The Pareto fronts generated by the multi-objective GA contain a region where models violate on average 2% of an application's constraints, compared to 2.8% for NSGA-II and 28.3% for the KLFA models. Similarly, it is possible to identify a region on the Pareto front where the multi-objective GA inferred models have an average bug detection ratio of 110 : 3 and the NSGA-II inferred models have an average bug detection ratio of 101 : 6. This compares to a bug detection ratio of 310928 : 13 for the KLFA tool.
Paolo Tonella, Alessandro Marchetto 0001, Duy Cu Nguyen, Yue Jia 0001, Kiran Lakhotia, Mark Harman
ICST3
2012 Revolution: Automatic Evolution of Mined Specifications
abstract
Specifications mined from execution traces are largely used to support testing and analysis of software applications with little runtime variability. However, when models are mined from applications that evolve at runtime, the resulting models become quickly obsolete, and thus of little support for any testing and analysis activity. To cope with such systems, mined specifications must be consistently updated every time the software changes. In principle, models can be periodically mined from scratch, but in many cases this solution is too expensive or even impossible. In this paper we describe Revolution, an approach for the automatic evolution of specifications mined by applying state abstraction techniques. Revolution produces models that are continuously updated and thus remain aligned with the actual implementation. Empirical results show that Revolution can suitably address run-time evolving applications.
Leonardo Mariani, Alessandro Marchetto 0001, Duy Cu Nguyen, Paolo Tonella, Arthur I. Baars
ISSRE3
2012 Combining model-based and combinatorial testing for effective test case generation
abstract
Model-based testing relies on the assumption that effective adequacy criteria can be defined in terms of model coverage achieved by a set of test paths. However, such test paths are only abstract test cases and input test data must be specified to make them concrete. We propose a novel approach that combines model-based and combinatorial testing in order to generate executable and effective test cases from a model. Our approach starts from a finite state model and applies model-based testing to generate test paths that represent sequences of events to be executed against the system under test. Such paths are transformed to classification trees, enriched with domain input specifications such as data types and partitions. Finally, executable test cases are generated from those trees using t-way combinatorial criteria.
Duy Cu Nguyen, Alessandro Marchetto 0001, Paolo Tonella
ISSTA1
2012 Evolutionary testing of autonomous software agents
Duy Cu Nguyen, Simon Miles, Anna Perini, Paolo Tonella, Mark Harman, Michael Luck
Auton. Agents Multi Agent Syst.1
2011 Test Case Prioritization for Audit Testing of Evolving Web Services Using Information Retrieval Techniques
abstract
Web services evolve frequently to meet new business demands and opportunities. However, service changes may affect service compositions that are currently consuming the services. Hence, audit testing (a form of regression testing in charge of checking for compatibility issues) is needed. As service compositions are often in continuous operation and the external services have limited (expensive) access when invoked for testing, audit testing has severe time and resources constraints, which make test prioritization a crucial technique (only the highest priority test cases will be executed).This paper presents a novel approach to the prioritization of audit test cases using information retrieval. This approach matches a service change description with the code portions exercised by the relevant test cases. So, test cases are prioritized based on their relevance to the service change. We evaluate the proposed approach on a system that composes services from eBay and Google.
Duy Cu Nguyen, Alessandro Marchetto 0001, Paolo Tonella
ICWS1