EDBT 2026 Demo / reviewers in the wild / expert
Bill Chu
dblp:92/6135
· DBLP profile ↗
24ranked-venue papers
0as first author
2since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 2 since 2021Human-computer interaction and ubiquitous computing · 8Computer networks · 3Software engineering, systems software and programming languages · 3Applied, interdisciplinary, general and emerging computing · 2Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Towards Automated and Explainable Threat Hunting with Generative AIabstractThis paper describes an attempt to automate threat hunting, taking cyber threat intelligence messages as input and generating queries to search logs for attack evidence using a popular query language, Kibana, used in Security Operations Centers (SOC). Our prototype implementation, AIThreatTrack, uses GPT-4 to extract actionable threat intelligence from real-time messages like X and Slack. The core idea is to explain the extracted intelligence in terms of MITRE ATT&CK TTPs using a knowledge graph containing "is-a" and "part-of" relationships (extracted using GPT-4) with the following benefits:(a) Significantly reduced hallucinations from 47% (GPT-4) to 1.5% using two orthogonal ways to cross-check answers. (b) Gaining analysts’ trust with explained results. (c) Using chain-of-knowledge prompting to significantly improve query generation accuracy. This approach supports expanding the scope of the knowledge graph to further improve query generation. Our approach significantly outperforms the Retrieval-Augmented Generation (RAG) approach and chain-of-thought reasoning LLM in reducing hallucinations. Moumita Das Purba, Bill Chu, Will French |
DSN | 2 |
| 2023 | Extracting Actionable Cyber Threat Intelligence from Twitter StreamabstractActionable cyber threat intelligence is vital for effective defense. In practice, indicators of compromises (IP addresses or domains) are used to alert potential malicious activities. However, such alerts lack important context for defenders to take effective actions. For example, given an alert concerning an IP address, a defender wants to know what type of malicious act (e.g., phishing website vs. C2) was observed associated with it. What technical manifestations (e.g., modification of a particular registry key) have been observed from the attacker using this IP address? Such context information helps defenders prioritize alerts and quickly determine whether a system has been compromised. Much of such context information exists in real-time information-sharing systems such as messaging apps and forums. This paper describes an approach to extract technical manifestations of attacks from tweets. We have compared our results with the performance of the GPT-3.5- Turbo model and text-embedding-ada-002 model of OpenAI and also created an open-source project to make our tools and data available for the cybersecurity research community [9]. Moumita Das Purba, Bill Chu |
ISI | 2 |
| 2020 | From Word Embedding to Cyber-Phrase Embedding: Comparison of Processing Cybersecurity TextsabstractMuch of the vital information about emerging threats and the corresponding defensive measures are contained in large volumes of natural language texts online. Capturing such actionable intelligence in real-time is critical to prevent large scale attacks automatically. The ATT&CK framework is a widely recognized standard to catalog technical details of cyber threats and deploy mitigating measures. A technique in ATT&CK specifies a set of adversary actions to achieve a particular goal, such as Exfiltration over Command and Control channel. Details of the technique include encrypted traffic and encoded data. A key challenge in identifying such cyber intelligence from natural language texts is that for a given action, such as encrypted traffic, many alternative expressions are possible (e.g., send using a self-signed certificate, send using HTTPS requests). It is not practical to manually provide an exhaustive list of all such variants. We demonstrate that using cyber-phrase embedding on a cybersecurity text corpus is a promising approach to overcome such difficulties. Our evaluation demonstrates that our model outperforms existing models. We have created an open-source project to make our tools and data available for the cybersecurity research community. Moumita Das Purba, Bill Chu, Ehab Al-Shaer |
ISI | 2 |
| 2019 | How Developers Diagnose Potential Security Vulnerabilities with a Static Analysis ToolabstractWhile using security tools to resolve security defects, software developers must apply considerable effort. Success depends on a developer's ability to interact with tools, ask the right questions, and make strategic decisions. To build better security tools and subsequently help developers resolve defects more accurately and efficiently, we studied the defect resolution process-from the questions developers ask to their strategies for answering them. In this paper, we report on an exploratory study with novice and experienced software developers. We equipped them with Find Security Bugs, a security-oriented static analysis tool, and observed their interactions with security vulnerabilities in an open-source system that they had previously contributed to. We found that they asked questions not only about security vulnerabilities, associated attacks, and fixes, but also questions about the software itself, the social ecosystem that built the software, and related resources and tools. We describe the strategic successes and failures we observed and how future tools can leverage our findings to encourage better strategies. Justin Smith 0001, Brittany Johnson, Emerson R. Murphy-Hill, Bill Chu, Heather Lipford |
IEEE Trans. Software Eng. | 4 |
| 2018 | Security During Application Development: an Application Security Expert PerspectiveabstractMany of the security problems that people face today, such as security breaches and data theft, are caused by security vulnerabilities in application source code. Thus, there is a need to understand and improve the experiences of those who can prevent such vulnerabilities in the first place - software developers as well as application security experts. Several studies have examined developers' perceptions and behaviors regarding security vulnerabilities, demonstrating the challenges they face in performing secure programming and utilizing tools for vulnerability detection. We expand upon this work by focusing on those primarily responsible for application security - security auditors. In an interview study of 32 application security experts, we examine their views on application security processes, their workflows, and their interactions with developers in order to further inform the design of tools and processes to improve application security. Tyler Thomas, Madiha Tabassum, Bill Chu, Heather Lipford |
CHI | 3 |
| 2018 | Using Entropy and Mutual Information to Extract Threat Actions from Cyber Threat IntelligenceabstractWith the rapid growth of the cyber attacks, cyber threat intelligence (CTI) sharing becomes essential for providing advance threat notice and enabling timely response to cyber attacks. Our goal in this paper is to develop an approach to extract low-level cyber threat actions from publicly available CTI sources in an automated manner to enable timely defense decision making. Specifically, we innovatively and successfully used the metrics of entropy and mutual information from Information Theory to analyze the text in the cybersecurity domain. Combined with some basic NLP techniques, our framework, called ActionMiner has achieved higher precision and recall than the state-of-the-art Stanford typed dependency parser, which usually works well in general English but not cybersecurity texts. Ghaith Husari, Xi Niu, Bill Chu, Ehab Al-Shaer |
ISI | 3 |
| 2018 | Evaluating Two Methods for Integrating Secure Programming EducationabstractSecurity vulnerabilities are still prevalent in today's software, yet many can be prevented with standard secure programming techniques. Thus, educators of future developers need to teach students not just how to program, but how to program securely. Many researchers advocate integrating secure programming knowledge and skills across the computer science curriculum. In this paper, we report the results of a study comparing two such methods: our own tool ESIDE, which provides students with security warnings on assignment code, and a security-clinic approach, a one-on-one session with a teaching assistant. Both methods suffered from challenges in incentivizing students to incorporate secure programming techniques into their code. We discuss the relative strengths and weaknesses of these methods, and the challenges of timing and motivation of secure programming education. Madiha Tabassum, Stacey Watson, Bill Chu, Heather Lipford |
SIGCSE | 3 |
| 2017 | TTPDrill: Automatic and Accurate Extraction of Threat Actions from Unstructured Text of CTI SourcesabstractWith the rapid growth of the cyber attacks, sharing of cyber threat intelligence (CTI) becomes essential to identify and respond to cyber attack in timely and cost-effective manner. However, with the lack of standard languages and automated analytics of cyber threat information, analyzing complex and unstructured text of CTI reports is extremely time- and labor-consuming. Without addressing this challenge, CTI sharing will be highly impractical, and attack uncertainty and time-to-defend will continue to increase. Ghaith Husari, Ehab Al-Shaer, Bill Chu, Xi Niu |
ACSAC | 4 |
| 2017 | The Design of Cyber Threat Hunting Games: A Case StudyabstractCyber Threat Hunting is an emerging cyber security activity. Recent studies show that, although similar actions like threat hunting are being actively practiced in some organization, security administrator and policy makers are far from being satisfied with their effectiveness. Most security professionals lack expertise in data analytics while most people with data analytics skills lack security knowledge. To understand the necessity of threat hunting education at university level, we organized a \textit{Threat Hunting Competition} on campus with generated logs. In this paper, we identify skills needed for cyber threat hunting, describe the data generation process as well as the usage of logs to teach threat hunting at universities. Md. Nazmus Sakib Miazi, Mir Mehedi Ahsan Pritom, Mohamed Shehab, Bill Chu, Jinpeng Wei |
ICCCN | 4 |
| 2017 | A Study on Log Analysis Approaches Using Sandia DatasetabstractModern enterprises collect, process, and analyze security data from various system and network logs. Previous studies show that, handling large security datasets and detecting anomalies from those are key challenges faced by most of todays' enterprises. Unfortunately most security professionals are inexperienced at performing data analysis. In this paper, we study published works analyzing one publicly accessible log dataset (Sandia Dataset) published by Los Alamos National Laboratory. We evaluate their data analysis methodology as well as results and found significant flaws in most analysis methodologies. Mir Mehedi Ahsan Pritom, Chuqin Li, Bill Chu, Xi Niu |
ICCCN | 3 |
| 2017 | Detecting Cross-Site Scripting Vulnerabilities through Automated Unit TestingabstractThe best practice to prevent Cross Site Scripting (XSS) attacks is to apply encoders to sanitize untrusted data. To balance security and functionality, encoders should be applied to match the web page context, such as HTML body, JavaScript, and style sheets. A common programming error is the use of a wrong encoder to sanitize untrusted data, leaving the application vulnerable. We present a security unit testing approach to detect XSS vulnerabilities caused by improper encoding of untrusted data. Unit tests for the XSS vulnerability are automatically constructed out of each web page and then evaluated by a unit test execution framework. A grammar-based attack generator is used to automatically generate test inputs. We evaluate our approach on a large open source medical records application, demonstrating that we can detect many 0-day XSS vulnerabilities with very low false positives, and that the grammar-based attack generator has better test coverage than industry best practices. Mahmoud Mohammadi, Bill Chu, Heather Lipford |
QRS | 2 |
| 2016 | Strategic Cyber Threat Intelligence Sharing: A Case Study of IDS LogsabstractCyber threat intelligence sharing is emerging as an important tool for network security as it can identify evolving threat patterns and prevent attackers from replicating their early success across the Internet. However the types of information sharing being practiced today are at the tactical level focusing on specific attacks, e.g. characteristics of a piece of malware, and black listed IP addresses and domains. In this paper we argue sharing cyber intelligence at a more strategic level is needed. By strategic information we mean information about salient common features of groups of attacks and attackers. Strategic information allows us to take actions that are much closer to the source of the attacks. For example instead of block an IP address as opposed to shutting down the botnet. We propose at set of strategic cyber threat indicators and show how they can be derived using an IDS log from a large commercial enterprise. Spike E. Dog, Alex Tweed, LeRoy Rouse, Bill Chu, Duan Qi, Yueqi Hu, Ehab Al-Shaer |
ICCCN | 4 |
| 2016 | Detecting Privilege Escalation Attacks through Instrumenting Web Application Source CodeabstractPrivilege Escalation is a common and serious type of security attack. Although experience shows that many applications are vulnerable to such attacks, attackers rarely succeed upon first trial. Their initial probing attempts often fail before a successful breach of access control is achieved. This paper presents an approach to automatically instrument application source code to report events of failed access attempts that may indicate privilege escalation attacks to a run time application protection mechanism. The focus of this paper is primarily on the problem of instrumenting web application source code to detect access control attack events. We evaluated false positives and negatives of our approach using two open source web applications. Jun Zhu 0002, Bill Chu, Heather Lipford |
SACMAT | 2 |
| 2015 | POSTER: Using Unit Testing to Detect Sanitization FlawsabstractInput sanitization mechanisms are widely used to mitigate vulnerabilities to injection attacks such as cross-site scripting. Static analysis tools and techniques commonly used to ensure that applications utilize sanitization functions. Dynamic analysis must be to evaluate the correctness of sanitization functions. The proposed approach is based on unit testing to bring the advantages of both static and dynamic techniques to the development time. Our approach introduces a technique to automatically extract the sanitization functions and then evaluate their effectiveness against attacks using automatically generated attack vectors. The empirical results show that the proposed technique can detect security flaws cannot find by the static analysis tools. Mahmoud Mohammadi, Bill Chu, Heather Lipford |
CCS | 2 |
| 2015 | Mitigating Access Control Vulnerabilities through Interactive Static AnalysisabstractAccess control vulnerabilities due to programming errors have consistently ranked amongst top software vulnerabilities. Previous research efforts have concentrated on using automatic program analysis techniques to detect access control vulnerabilities in applications. We report a comparative study of six open source PHP applications, and find that implicit assumptions of previous research techniques can significantly limit their effectiveness. We propose a more effective hybrid approach to mitigate access control vulnerabilities. Developers are reminded in-situ of potential access control vulnerabilities, where self-review of code can help them discover mistakes. Additionally, developers are prompted for application-specific access control knowledge, providing samples of code that could be thought of as static analysis by example. These examples are turned into code patterns that can be used in performing static analysis to detect additional access control vulnerabilities and alert the developer to take corrective actions. Our evaluation of six open source applications detected 20 zero-day access control vulnerabilities in addition to finding all access control vulnerabilities detected in previous works. Jun Zhu 0002, Bill Chu, Heather Lipford, Tyler Thomas |
SACMAT | 2 |
| 2015 | Embedding Secure Coding Instruction into the IDE: A Field Study in an Advanced CS CourseabstractMany of the security vulnerabilities common in today's software can be prevented with standard secure coding practices. Computer science students who will become the developers of that software need to learn about those practices so they can prevent such vulnerabilities. Many computing programs are addressing this need through additional lectures, elective courses, or more holistic approaches to integrate security across curriculums. We are exploring a complementary approach, integrating secure coding education into the IDE to provide a learning opportunity in the context of writing code. In this paper, we report on two field studies using an IDE tool in an advanced Web programming course. Our results indicate that the tool can increase students' awareness and knowledge of secure programming, but to be most effective, instructors may need to incentivize its use through in-class methods and careful timing of its introduction. Michael Whitney, Heather Lipford, Bill Chu, Jun Zhu 0002 |
SIGCSE | 3 |
| 2015 | Questions developers ask while diagnosing potential security vulnerabilities with static analysisabstractSecurity tools can help developers answer questions about potential vulnerabilities in their code. A better understanding of the types of questions asked by developers may help toolsmiths design more effective tools. In this paper, we describe how we collected and categorized these questions by conducting an exploratory study with novice and experienced software developers. We equipped them with Find Security Bugs, a security-oriented static analysis tool, and observed their interactions with security vulnerabilities in an open-source system that they had previously contributed to. We found that they asked questions not only about security vulnerabilities, associated attacks, and fixes, but also questions about the software itself, the social ecosystem that built the software, and related resources and tools. For example, when participants asked questions about the source of tainted data, their tools forced them to make imperfect tradeoffs between systematic and ad hoc program navigation strategies. Justin Smith 0001, Brittany Johnson, Emerson R. Murphy-Hill, Bill Chu, Heather Lipford |
ESEC/SIGSOFT FSE | 4 |
| 2015 | A study of interactive code annotation for access control vulnerabilitiesabstractWhile there are a variety of existing tools to help detect security vulnerabilities in code, they are seldom used by developers due to the time or security expertise required. We are investigating techniques integrated within the IDE to help developers detect and mitigate security vulnerabilities. In this paper, we examine using interactive annotation for access control vulnerabilities. We evaluated whether developers could indicate access control logic using interactive annotation and understand the vulnerabilities reported as a result. Our study indicates that developers can easily find and annotate access control logic but can struggle to use our tool to trace the cause of the vulnerability. Our results provide design guidance for improving the interaction and communication of such security tools with developers. Tyler Thomas, Bill Chu, Heather Lipford, Justin Smith 0001, Emerson R. Murphy-Hill |
VL/HCC | 2 |
| 2014 | SIW 2014: First Workshop on Security Information WorkersabstractThe human element is often considered the weakest element in security. Although many kinds of humans interact with systems that are designed to be secure, one particular type of human is especially important, the security information worker. Security information workers include software developers, system administrators, and intelligence analysts. This workshop aims to develop and stimulate discussion about security information workers. Emerson R. Murphy-Hill, Heather Lipford, Bill Chu, Robert Biddle |
CCS | 3 |
| 2013 | Interactive support for secure programming educationabstractSoftware flaws are a root cause of many of today's information security vulnerabilities. Current curricula emphasis on traditional information security issues does not address this root cause. We propose educating students on secure programming techniques through interactive tool support in the Integrated Development Environment (IDE). We believe this approach can complement other curricula efforts by teaching and providing continuous reinforcement of practices throughout programming tasks. In this paper, we evaluate our prototype tool, ASIDE, which provides instant security warnings, detailed explanations of vulnerabilities, and code generation. We report the results of an observational study on 20 students from an advanced Web programming course. The results provide early evidence that our tool could potentially help students learn about and practice secure programming in the context of their programming assignments. Jun Zhu 0002, Heather Lipford, Bill Chu |
SIGCSE | 3 |
| 2011 | ASIDE: IDE support for web application securityabstractMany of today's application security vulnerabilities are introduced by software developers writing insecure code. This may be due to either a lack of understanding of secure programming practices, and/or developers' lapses of attention on security. Much work on software security has focused on detecting software vulnerabilities through automated analysis techniques. While they are effective, we believe they are not sufficient. We propose to increase developer awareness and promote practice of secure programming by interactively reminding programmers of secure programming practices inside Integrated Development Environments (IDEs). We have implemented a proof-of-concept plugin for Eclipse and Java. Initial evaluation results show that this approach can detect and address common web application vulnerabilities and can serve as an effective aid for programmers. Our approach can also effectively complement existing software security best practices and significantly increase developer productivity. Jing Xie 0011, Bill Chu, Heather Lipford, John T. Melton |
ACSAC | 2 |
| 2011 | The Design and Implementation of a Cryptographic Education Tool
Abdrah Abuzaid, Xiaohong Yuan, Huiming Yu, Bill Chu |
CSEDU (1) | 4 |
| 2011 | Why do programmers make security errors?abstractA large number of software security vulnerabilities are caused by software errors that are committed by software developers. We believe that interactive tool support will play an important role in aiding software developers to develop more secure software. However, an in-depth understanding of how and why software developers produce security bugs is needed to design such tools. We conducted a semi-structured interview study on 15 professional software developers to understand their perceptions and behaviors related to software security. Our results reveal a disconnect between developers' conceptual understanding of security and their attitudes regarding their personal responsibility and practices for software security. Jing Xie 0011, Heather Lipford, Bill Chu |
VL/HCC | 3 |
| 2003 | Authorization management for role-based collaborationabstractInformation sharing among collaborating organizations usually occurs in broad, highly dynamic network-based environments, and formally accessing the resources in a secure manner poses a difficult challenge. The mechanisms must be provided to protect the resources from adversaries. The proposed delegation framework addresses the issue of how to advocate selective information sharing among collaborating organizations. We introduce a systematic approach to manage delegated privileges with the specification of delegation and revocation policies using a set of rules. We demonstrate the feasibility of our approach by providing a proof-of-concept implementation. We also briefly discuss several issues from our experiment including future directions. Gail-Joon Ahn, Longhua Zhang, Dongwan Shin, Bill Chu |
SMC | 4 |