Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Ilya Kosorukov

dblp:393/9557 · DBLP profile ↗
← Back
1ranked-venue papers
1as first author
1since 2021 · last 2024
0009-0000-9832-7295ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Debugging and program repair · 100%
Network and information security
1 paper
Systems and software security · 100%

Topics — the 3 heaviest of 3, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
information flow control
0.812024
Mining for Mutation Operators for Reduction of Information Flow Control Violations · ASE 2024
Debugging and program repair
automated program repair
0.812024
Mining for Mutation Operators for Reduction of Information Flow Control Violations · ASE 2024
Debugging and program repair › automated program repair
mutation-based repair
0.812024
Mining for Mutation Operators for Reduction of Information Flow Control Violations · ASE 2024

Methods — techniques the papers use, named apart from their topics

mutation operators · 1.5hypertesting · 1.5genetic improvement · 1.5
YearPublicationVenuePosition
2024 Mining for Mutation Operators for Reduction of Information Flow Control Violations
abstract
The unintentional flow of confidential data to unauthorised users is a serious software security vulnerability. Detection and repair of such errors is a non-trivial task that has been worked on by the security community for many years. More recently, dynamic approaches, such as HyperGI, have been introduced that use hypertesting and genetic improvement to not only detect, but also provide a patch that reduces such information flow control violations. However, empirical studies performed so far have used mostly generic mutation operators, potentially limiting the strength of this approach. In this new ideas paper we mine the National Vulnerabilities Database to find repairs of information leaks. Of 636 issues initially identified, we found 73 fixes that relate to information leaks and come with open source patches to the code. From these, we identified 10 types of mutation operators with potential to fix such issues. Six of these have so far never been used to fix information leaks via automated mutation to the code. We propose that these could help improve effectiveness of tools using the HyperGI approach.
Ilya Kosorukov, Daniel Blackwell, David Clark 0001, Myra B. Cohen, Justyna Petke
ASE1