VLDB 2026 Research / reviewers in the wild / expert
Pingyan Wang
dblp:345/0770
· DBLP profile ↗
3ranked-venue papers
3as first author
3since 2021 · last 2024
0000-0002-1085-5999ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 3 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Toward Pointer-Analysis-Based Vulnerability Discovery in Human-Machine Pair ProgrammingabstractPointer analysis is the underlying technique of many static analysis tools for vulnerability discovery. It has proved to be effective in identifying a variety of vulnerabilities, such as buffer overflow vulnerabilities and injection vulnerabilities. However, most existing pointer analysis approaches require whole-program availability, i.e. the program to be analyzed should be complete, which may hinder a timely analysis during the coding phase. In this paper, we present two approaches, exhaustive and demand-driven pointer analyses, both of which are applied to a paradigm known as Human–Machine Pair Programming. The ideas enable us to discover security flaws as early as in the coding phase. In this paper, we describe in detail how our approaches maintain flow sensitivity and propagate points-to and taint information in an incremental fashion. We conduct an evaluation of our approaches on SecuriBench Micro and show that the approaches can capture all the potential vulnerabilities in the test cases, though several false alarms are reported. Pingyan Wang, Shaoying Liu |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 2024 | Detecting security vulnerabilities with vulnerability nets
Pingyan Wang, Shaoying Liu, Ai Liu |
J. Syst. Softw. | 1 |
| 2023 | Detecting Security Vulnerabilities in Human-Machine Pair Programming with Pointer AnalysisabstractPointer analysis is the underlying technique of many static analysis tools for vulnerability discovery. Most existing pointer analysis approaches require whole-program availability, i.e., a program to be analyzed should be complete, which may hinder a timely analysis during the coding phase. By contrast, the attempt of this work is to perform analyses in Human-Machine Pair Programming, where the programs being analyzed are still under construction. Analyzing such incomplete programs enables programmers to discover security flaws as early as in the coding phase. In the paper we describe in detail how our approach maintains flow sensitivity and propagates points-to and taint information in an incremental fashion. We demonstrate the feasibility of our approach by conducting an experiment on a security benchmark. The experiment results show that our approach can capture all the potential vulnerabilities in the test cases in real time, though a number of false alarms are reported. Pingyan Wang, Shaoying Liu |
ICECCS | 1 |