16 papers · ranked by Valyu relevance
Marcel Böhme, Eric Bodden, Tevfik Bultan, Cristian Cadar + 2 more
'Giuseppe Scanniello'] As our lives, our businesses, and indeed our world economy become increasingly reliant on the secure operation of many interconnected software systems, the software engineering research community is faced with unprecedented research challenges, but also with exciting new opportunities. In this…
Xu Zhou, Pengfei Wang, Lei Zhou, Peng Xun + 2 more
'Ramon Gonzalez Carvajal'] Embedded devices are pervasive nowadays with the rapid development of the Internet of Things (IoT). This brings significant security issues that make the security analysis of embedded devices important. This paper presents a survey on the security analysis research of embedded devices. First…
Muhammad Aufeef Chauhan, Muhammad Ali Babar, Fethi Rabhi
Orchestration, Analysis and Reporting Authors: ['Muhammad Aufeef Chauhan' 'Muhammad Ali Babar' 'Fethi Rabhi'] A Software Reference Architecture (SRA) is a useful tool for standardising existing architectures in a specific domain and facilitating concrete architecture design, development and evaluation by instantiating…
Osejobe Ehichoya, Chinwuba Christian Nnaemeka
—Web services are becoming business-critical components, often deployed with critical software bugs that can be maliciously explored. Web vulnerability scanners allow the detection of security vulnerabilities in web services by stressing the service from the point of view of an attacker. However, research and practice…
Faheem Ullah, Muhammad Ali Babar
Context: Big Data Cybersecurity Analytics is increasingly becoming an important area of research and practice aimed at protecting networks, computers, and data from unauthorized access by analysing security event data using big data tools and technologies. Whilst a plethora of Big Data Cybersecurity Analytic Systems…
Krish Jain, John Sum, Pranav Kapoor, Amir Eaman
—Analysis of Security-Enhanced Linux (SELinux) policies requires extensive manual effort to identify violations and security misconfigurations. Current tools employ mathematical abstractions that, while theoretically sound, produce outputs that practitioners struggle to interpret effectively. Automated approaches using…
Katja Tuma, Winnie Mbaka
Background: Organizations are experiencing an increasing demand for security-by-design activities (e.g., STRIDE analyses) which require a high manual effort. This situation is worsened by the current lack of diverse (and sufficient) security workforce and inconclusive results from past studies. To date, the deciding…
Björn Lundgren, Niklas Möller
This article proposes a new definition of information security, the ‘Appropriate Access’ definition. Apart from providing the basic criteria for a definition-correct demarcation and meaning concerning the state of security-it also aims at being a definition suitable for any information security perspective. As such, it…
Yong Fang, Shengjun Han, Cheng Huang, Runpu Wu + 1 more
With the widespread usage of Web applications, the security issues of source code are increasing. The exposed vulnerabilities seriously endanger the interests of service providers and customers. There are some models for solving this problem. However, most of them rely on complex graphs generated from source code or…
Jiazhen Zhao, Kailong Zhu, Canju Lu, Jun Zhao + 2 more
PHP is the most widely used server-side programming language, but it remains highly susceptible to diverse classes of vulnerabilities. Static Application Security Testing (SAST) tools are commonly adopted for vulnerability detection; however, their evaluation lacks systematic criteria capable of quantifying information…
Garrett J. Schumacher, Sterling Sawaya, Demetrius King, Aaron J. Hansen
Genetic information is being generated at an increasingly rapid pace, offering advances in science and medicine that are paralleled only by the threats and risk present within the responsible ecosystem. Human genetic information is identifiable and contains sensitive information, but genetic data security is only…
Cláudia Brito, Pedro Ferreira, João Paulo
Breakthroughs in sequencing technologies led to an exponential growth of genomic data, providing unprecedented biological in-sights and new therapeutic applications. However, analyzing such large amounts of sensitive data raises key concerns regarding data privacy, specifically when the information is outsourced to…
Natnatee Dokmai, Kaiyuan Zhu, S. Cenk Sahinalp, Hyunghoon Cho
Genotype imputation servers enable researchers with limited resources to extract valuable insights from their data with enhanced accuracy and ease. However, the utility of these services is limited for those with sensitive study cohorts or those in restrictive regulatory environments due to data privacy concerns.…
Robson de Oliveira Albuquerque, Luis Javier García Villalba, Ana Lucila Sandoval Orozco, Fábio Buiati + 1 more
'Ana Lucila Sandoval Orozco' 'Fábio Buiati' 'Tai-Hoon Kim'] Information can be considered the most important asset of any modern organization. Securing this information involves preserving confidentially, integrity and availability, the well-known CIA triad. In addition, information security is a risk management job…
Chih Chuan Shih, Jieqi Chen, Ai Shan Lee, Nicolas Bertin + 34 more
Genomic researchers are increasingly utilizing commercial cloud platforms (CCPs) to manage their data and analytics needs. Commercial clouds allow researchers to grow their storage and analytics capacity on demand, keeping pace with expanding project data footprints and enabling researchers to avoid large capital…
James Casaletto, Michael Parsons, Charles Markello, Yusuke Iwasaki + 3 more
More than 40% of the germline variants in ClinVar today are variants of uncertain significance (VUS). These variants remain unclassified in part because the patient-level data needed for their interpretation is siloed. Federated analysis can overcome this problem by “bringing the code to the data”: analyzing the…