Michael Eichberg

dblp:66/3818 · DBLP profile ↗
← Back
22ranked-venue papers
8as first author
2since 2021 · last 2025
0009-0005-4864-1864ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 19 · 8 first-authorDatabases, data management, data science and information retrieval · 3 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
11 papers
Program analysis · 84% Software maintenance and evolution · 15% Requirements engineering and software design · 0%
Network and information security
2 papers
Web and mobile security · 65% Systems and software security · 35%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Parallel and multicore computing · 100%

Topics — the 23 heaviest of 25, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Program analysis
static analysis
1.762020
A programming model for semi-implicit parallelization of static analyses · ISSTA 2020
Judge: identifying, understanding, and evaluating sources of unsoundness in call graphs · ISSTA 2019
A unified lattice model and framework for purity analyses · ASE 2018
Program analysis › static analysis › static analysis tools
static analysis framework
0.412020
Modular collaborative program analysis in OPAL · ESEC/SIGSOFT FSE 2020
Parallel and multicore computing
parallel programming models
0.412020
A programming model for semi-implicit parallelization of static analyses · ISSTA 2020
Program analysis
data flow analysis
0.422020
Call graph construction for Java libraries · SIGSOFT FSE 2016
A programming model for semi-implicit parallelization of static analyses · ISSTA 2020
Program analysis › static analysis › interprocedural analysis
call graph analysis
0.412019
Judge: identifying, understanding, and evaluating sources of unsoundness in call graphs · ISSTA 2019
Program analysis › static analysis
call graph construction
0.422019
Call graph construction for Java libraries · SIGSOFT FSE 2016
Judge: identifying, understanding, and evaluating sources of unsoundness in call graphs · ISSTA 2019
Program analysis › static analysis › abstract interpretation
lattice-based analysis
0.312018
A unified lattice model and framework for purity analyses · ASE 2018
Program analysis › effect analysis
side-effect analysis
0.312018
A unified lattice model and framework for purity analyses · ASE 2018
Web and mobile security
mobile security
0.312017
CodeMatch: obfuscation won't conceal your repackaged app · ESEC/SIGSOFT FSE 2017
Web and mobile security › mobile security
repackaged app detection
0.312017
CodeMatch: obfuscation won't conceal your repackaged app · ESEC/SIGSOFT FSE 2017
Software maintenance and evolution › software ecosystems
library identification
0.312017
CodeMatch: obfuscation won't conceal your repackaged app · ESEC/SIGSOFT FSE 2017
Software maintenance and evolution
software ecosystems
0.312017
CodeMatch: obfuscation won't conceal your repackaged app · ESEC/SIGSOFT FSE 2017
Program analysis › static analysis
interprocedural analysis
0.212016
Call graph construction for Java libraries · SIGSOFT FSE 2016
Software maintenance and evolution › code smell
code smell detection
0.212015
Hidden truths in dead software paths · ESEC/SIGSOFT FSE 2015
Program analysis › control flow analysis
infeasible path detection
0.212015
Hidden truths in dead software paths · ESEC/SIGSOFT FSE 2015
Program analysis
library analysis
0.212015
Getting to know you: towards a capability model for Java · ESEC/SIGSOFT FSE 2015
Program analysis › data flow analysis
IFDS-based analysis
0.112020
A programming model for semi-implicit parallelization of static analyses · ISSTA 2020
Software maintenance and evolution › software dependencies
code dependencies
0.112008
Defining and continuous checking of structural program dependencies · ICSE 2008
Program analysis › static analysis
abstract interpretation
0.112015
Hidden truths in dead software paths · ESEC/SIGSOFT FSE 2015
Program analysis › static analysis
incremental analysis
0.112006
Integrating and Scheduling an Open Set of Static Analyses · ASE 2006
Software maintenance and evolution
program comprehension
0.112006
The SEXTANT Software Exploration Tool · IEEE Trans. Software Eng. 2006
Requirements engineering and software design
software architecture
0.012008
Defining and continuous checking of structural program dependencies · ICSE 2008
Software maintenance and evolution › program comprehension
software visualization
0.012006
The SEXTANT Software Exploration Tool · IEEE Trans. Software Eng. 2006

Methods — techniques the papers use, named apart from their topics

scheduling strategies · 0.9reactive programming · 0.9monotonic computation · 0.9static analysis · 0.5imperative analysis · 0.4declarative analysis · 0.4test suite · 0.4empirical evaluation · 0.4modular analysis · 0.3lattice model · 0.3library code removal · 0.3fuzzy hashing · 0.3bytecode abstraction · 0.3
YearPublicationVenuePosition
2025 SCAPE Semantically Context-Aware Password Generation Using Word Embeddings
Nadine Sarah Schüler, Maximilian von Zastrow, Tobias Vent, Michael Eichberg
SISAP4
2022 SePass: Semantic Password Guessing Using k-nn Similarity Search in Word Embeddings
Maximilian von Zastrow, Levin Schäfer, Nadine Sarah Schüler, Michael Eichberg, Peer Kröger
ADMA (2)4
2020 A programming model for semi-implicit parallelization of static analyses
abstract
Parallelization of static analyses is necessary to scale to real-world programs, but it is a complex and difficult task and, therefore, often only done manually for selected high-profile analyses. In this paper, we propose a programming model for semi-implicit parallelization of static analyses which is inspired by reactive programming. Reusing the domain-expert knowledge on how to parallelize anal- yses encoded in the programming framework, developers do not need to think about parallelization and concurrency issues on their own. The programming model supports stateful computations, only requires monotonic computations over lattices, and is independent of specific analyses. Our evaluation shows the applicability of the programming model to different analyses and the importance of user-selected scheduling strategies. We implemented an IFDS solver that was able to outperform a state-of-the-art, specialized parallel IFDS solver both in absolute performance and scalability.
Dominik Helm, Florian Kübler, Jan Thomas Kölzer, Philipp Haller, Michael Eichberg, Guido Salvaneschi, Mira Mezini
ISSTA5
2020 Modular collaborative program analysis in OPAL
abstract
Current approaches combining multiple static analyses deriving different, independent properties focus either on modularity or performance. Whereas declarative approaches facilitate modularity and automated, analysis-independent optimizations, imperative approaches foster manual, analysis-specific optimizations.
Dominik Helm, Florian Kübler, Michael Reif, Michael Eichberg, Mira Mezini
ESEC/SIGSOFT FSE4
2019 Judge: identifying, understanding, and evaluating sources of unsoundness in call graphs
abstract
Call graphs are widely used; in particular for advanced control- and data-flow analyses. Even though many call graph algorithms with different precision and scalability properties have been proposed, a comprehensive understanding of sources of unsoundness, their relevance, and the capabilities of existing call graph algorithms in this respect is missing. To address this problem, we propose Judge, a toolchain that helps with understanding sources of unsoundness and improving the soundness of call graphs. In several experiments, we use Judge and an extensive test suite related to sources of unsoundness to (a) compute capability profiles for call graph implementations of Soot, WALA, DOOP, and OPAL, (b) to determine the prevalence of language features and APIs that affect soundness in modern Java Bytecode, (c) to compare the call graphs of Soot, WALA, DOOP, and OPAL – highlighting important differences in their implementations, and (d) to evaluate the necessary effort to achieve project-specific reasonable sound call graphs. We show that soundness-relevant features/APIs are frequently used and that support for them differs vastly, up to the point where comparing call graphs computed by the same base algorithms (e.g., RTA) but different frameworks is bogus. We also show that Judge can support users in establishing the soundness of call graphs with reasonable effort.
Michael Reif, Florian Kübler, Michael Eichberg, Dominik Helm, Mira Mezini
ISSTA3
2019 A dataset of parametric cryptographic misuses
abstract
Cryptographic APIs (Crypto APIs) provide the foundations for the development of secure applications. Unfortunately, most applications do not use Crypto APIs securely and end up being insecure, e.g., by the usage of an outdated algorithm, a constant initialization vector, or an inappropriate hashing algorithm. Two different studies [1], [2] have recently shown that 88% to 95% of those applications using Crypto APIs are insecure due to misuses. To facilitate further research on these kinds of misuses, we created a collection of 201 misuses found in real-world applications along with a classification of those misuses. In the provided dataset, each misuse consists of the corresponding open-source project, the project's build information, a description of the misuse, and the misuse's location. Further, we integrated our dataset into MUBench [3], a benchmark for API misuse detection. Our dataset provides a foundation for research on Crypto API misuses. For example, it can be used to evaluate the precision and recall of detection tools, as a foundation for studies related to Crypto API misuses, or as a training set.
Anna-Katharina Wickert, Michael Reif, Michael Eichberg, Anam Dodhy, Mira Mezini
MSR3
2018 A unified lattice model and framework for purity analyses
abstract
Analyzing methods in object-oriented programs whether they are side-effect free and also deterministic, i.e., mathematically pure, has been the target of extensive research. Identifying such methods helps to find code smells and security related issues, and also helps analyses detecting concurrency bugs. Pure methods are also used by formal verification approaches as the foundations for specifications and proving the pureness is necessary to ensure correct specifications. However, so far no common terminology exists which describes the purity of methods. Furthermore, some terms (e.g., pure or side-effect free) are also used inconsistently. Further, all current approaches only report selected purity information making them only suitable for a smaller subset of the potential use cases. In this paper, we present a fine-grained unified lattice model which puts the purity levels found in the literature into relation and which adds a new level that generalizes existing definitions. We have also implemented a scalable, modularized purity analysis which produces significantly more precise results for real-world programs than the best-performing related work. The analysis shows that all defined levels are found in real-world projects.
Dominik Helm, Florian Kübler, Michael Eichberg, Michael Reif, Mira Mezini
ASE3
2017 CodeMatch: obfuscation won't conceal your repackaged app
abstract
An established way to steal the income of app developers, or to trick users into installing malware, is the creation of repackaged apps. These are clones of - typically - successful apps. To conceal their nature, they are often obfuscated by their creators. But, given that it is a common best practice to obfuscate apps, a trivial identification of repackaged apps is not possible. The problem is further intensified by the prevalent usage of libraries. In many apps, the size of the overall code base is basically determined by the used libraries. Therefore, two apps, where the obfuscated code bases are very similar, do not have to be repackages of each other. To reliably detect repackaged apps, we propose a two step approach which first focuses on the identification and removal of the library code in obfuscated apps. This approach - LibDetect - relies on code representations which abstract over several parts of the underlying bytecode to be resilient against certain obfuscation techniques. Using this approach, we are able to identify on average 70% more used libraries per app than previous approaches. After the removal of an app's library code, we then fuzzy hash the most abstract representation of the remaining app code to ensure that we can identify repackaged apps even if very advanced obfuscation techniques are used. This makes it possible to identify repackaged apps. Using our approach, we found that ≈ 15% of all apps in Android app stores are repackages
Leonid Glanz, Sven Amann, Michael Eichberg, Michael Reif, Ben Hermann, Johannes Lerch, Mira Mezini
ESEC/SIGSOFT FSE3
2016 Call graph construction for Java libraries
abstract
Today, every application uses software libraries. Yet, while a lot of research exists w.r.t. analyzing applications, research that targets the analysis of libraries independent of any application is scarce. This is unfortunate, because, for developers of libraries, such as the Java Development Kit (JDK), it is crucial to ensure that the library behaves as intended regardless of how it is used. To fill this gap, we discuss the construction of call graphs for libraries that abstract over all potential library usages. Call graphs are particularly relevant as they are a precursor of many advanced analyses, such as inter-procedural data-flow analyses.
Michael Reif, Michael Eichberg, Ben Hermann, Johannes Lerch, Mira Mezini
SIGSOFT FSE2
2015 Hidden truths in dead software paths
abstract
Approaches and techniques for statically finding a multitude of issues in source code have been developed in the past. A core property of these approaches is that they are usually targeted towards finding only a very specific kind of issue and that the effort to develop such an analysis is significant. This strictly limits the number of kinds of issues that can be detected. In this paper, we discuss a generic approach based on the detection of infeasible paths in code that can discover a wide range of code smells ranging from useless code that hinders comprehension to real bugs. Code issues are identified by calculating the difference between the control-flow graph that contains all technically possible edges and the corresponding graph recorded while performing a more precise analysis using abstract interpretation. We have evaluated the approach using the Java Development Kit as well as the Qualitas Corpus (a curated collection of over 100 Java Applications) and were able to find thousands of issues across a wide range of categories.
Michael Eichberg, Ben Hermann, Mira Mezini, Leonid Glanz
ESEC/SIGSOFT FSE1
2015 Getting to know you: towards a capability model for Java
abstract
Developing software from reusable libraries lets developers face a security dilemma: Either be efficient and reuse libraries as they are or inspect them, know about their resource usage, but possibly miss deadlines as reviews are a time consuming process. In this paper, we propose a novel capability inference mechanism for libraries written in Java. It uses a coarse-grained capability model for system resources that can be presented to developers. We found that the capability inference agrees by 86.81% on expectations towards capabilities that can be derived from project documentation. Moreover, our approach can find capabilities that cannot be discovered using project documentation. It is thus a helpful tool for developers mitigating the aforementioned dilemma.
Ben Hermann, Michael Reif, Michael Eichberg, Mira Mezini
ESEC/SIGSOFT FSE3
2013 Incremental concrete syntax for embedded languages with support for separate compilation
Tom Dinkelaker, Michael Eichberg, Mira Mezini
Sci. Comput. Program.2
2012 What should developers be aware of? An empirical study on the directives of API documentation
Martin Monperrus, Michael Eichberg, Elif Tekes, Mira Mezini
Empir. Softw. Eng.2
2010 Model-Driven Engineering of Machine Executable Code
Michael Eichberg, Martin Monperrus, Sven Kloppenburg, Mira Mezini
ECMFA1
2008 Defining and continuous checking of structural program dependencies
abstract
Dependencies between program elements need to be modeled from different perspectives reflecting architectural, design, and implementation level decisions. To avoid erosion of the intended structure of the code, it is necessary to explicitly codify these different perspectives on the permitted dependencies and to detect violations continuously and incrementally as software evolves.
Michael Eichberg, Sven Kloppenburg, Karl Klose, Mira Mezini
ICSE1
2007 Automatic Incrementalization of Prolog Based Static Analyses
Michael Eichberg, Matthias Kahl, Diptikalyan Saha, Mira Mezini, Klaus Ostermann
PADL1
2006 Integrating and Scheduling an Open Set of Static Analyses
abstract
To improve the productivity of the development process, more and more tools for static software analysis are tightly integrated into the incremental build process of an IDE. If multiple interdependent analyses are used simultaneously, the coordination between the analyses becomes a major obstacle to keep the set of analyses open. We propose an approach to integrating and scheduling an open set of static analyses which decouples the individual analyses and coordinates the analysis executions such that the overall time and space consumption is minimized. The approach has been implemented for the Eclipse IDE and has been used to integrate a wide range of analyses such as finding bug patterns, detecting violations of design guidelines, or type system extensions for Java
Michael Eichberg, Mira Mezini, Sven Kloppenburg, Klaus Ostermann, Benjamin Rank
ASE1
2006 The SEXTANT Software Exploration Tool
abstract
In this paper, we discuss a set of functional requirements for software exploration tools and provide initial evidence that various combinations of these features are needed to effectively assist developers in understanding software. We observe that current tools for software exploration only partly support these features. This has motivated the development of SEXTANT, a software exploration tool tightly integrated into the Eclipse IDE that has been developed to fill this gap. By means of case studies, we demonstrate how the requirements fulfilled by SEXTANT are conducive to an understanding needed to perform a maintenance task
Thorsten Schäfer, Michael Eichberg, Michael Haupt 0003, Mira Mezini
IEEE Trans. Software Eng.2
2005 Using Annotations to Check Structural Properties of Classes
Michael Eichberg, Thorsten Schäfer, Mira Mezini
FASE1
2005 Comprehensive Software Understanding with SEXTANT
abstract
Current tools for software understanding mostly concentrate on one comprehension technique, e.g., visualization, or bottom-up navigation through software elements via hyperlinks. In this paper, we argue that to effectively assist developers in understanding today's software systems, a combination of several comprehension techniques is needed including seamless integration of top-down querying and bottom-up navigation strategies that work across different kinds of software artifacts; furthermore, application-domain and/or technology specific relationships between software elements should be taken into consideration; last but not least, a tight integration of such tools into development environments is crucial. We present SEXTANT, a software exploration tool tightly integrated into the Eclipse IDE that satisfies these requirements. In two case studies, we demonstrate how SEXTANT's features are conducive in tracking down the source of erroneous behavior, respectively, in discovering 'bad smells' in the software structure which should lead to code refactorings.
Michael Eichberg, Michael Haupt 0003, Mira Mezini, Thorsten Schäfer
ICSM1
2005 An execution layer for aspect-oriented programming languages
abstract
Language mechanisms deserve language implementation effort. While this maxim has led to sophisticated support for language features specific to object-oriented, functional and logic programming languages, aspect-oriented programming languages are still mostly implemented using postprocessors. The Steamloom virtual machine, based on IBM's Jikes RVM, provides support for aspect-oriented programming at virtual machine level. A bytecode framework called BAT was integrated with the Jikes RVM to replace its bytecode management logic. While preserving the functionality needed by the VM, BAT also allows for querying application code for join point shadows, avoiding redundancy in bytecode representation. Performance measurements show that an AOP-enabled virtual machine like Steamloom does not inflict unnecessary performance penalties on a running application; when it comes to executing AOP-related operations, there even are significant performance gains compared to other approaches.
Michael Haupt 0003, Mira Mezini, Christoph Bockisch, Tom Dinkelaker, Michael Eichberg, Michael Krebs
VEE5
2004 Pointcuts as Functional Queries
Michael Eichberg, Mira Mezini, Klaus Ostermann
APLAS1