Search Results - "Croft, Roland"
-
1
Data Preparation for Software Vulnerability Prediction: A Systematic Literature Review
Published in IEEE transactions on software engineering (01-03-2023)“…Software Vulnerability Prediction (SVP) is a data-driven technique for software quality assurance that has recently gained considerable attention in the…”
Get full text
Journal Article -
2
SmartValidator: A framework for automatic identification and classification of cyber threat data
Published in Journal of network and computer applications (01-06-2022)“…A wide variety of Cyber Threat Information (CTI) is used by Security Operation Centres (SOCs) to perform validation of security incidents and alerts. Security…”
Get full text
Journal Article -
3
An Investigation into Inconsistency of Software Vulnerability Severity across Data Sources
Published in 2022 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER) (01-03-2022)“…Software Vulnerability (SV) severity assessment is a vital task for informing SV remediation and triage. Ranking of SV severity scores is often used to advise…”
Get full text
Conference Proceeding -
4
Data Quality for Software Vulnerability Datasets
Published in 2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE) (01-05-2023)“…The use of learning-based techniques to achieve automated software vulnerability detection has been of longstanding interest within the software security…”
Get full text
Conference Proceeding -
5
DeepCVA: Automated Commit-level Vulnerability Assessment with Deep Multi-task Learning
Published in 2021 36th IEEE/ACM International Conference on Automated Software Engineering (ASE) (01-11-2021)“…It is increasingly suggested to identify Software Vulnerabilities (SVs) in code commits to give early warnings about potential security risks. However, there…”
Get full text
Conference Proceeding -
6
An empirical study of developers’ discussions about security challenges of different programming languages
Published in Empirical software engineering : an international journal (01-01-2022)“…Given programming languages can provide different types and levels of security support, it is critically important to consider security aspects while selecting…”
Get full text
Journal Article -
7
Noisy Label Learning for Security Defects
Published in 2022 IEEE/ACM 19th International Conference on Mining Software Repositories (MSR) (01-05-2022)“…Data-driven software engineering processes, such as vulnerability prediction heavily rely on the quality of the data used. In this paper, we observe that it is…”
Get full text
Conference Proceeding -
8
Data Quality for Software Vulnerability Datasets
Published 13-01-2023“…The use of learning-based techniques to achieve automated software vulnerability detection has been of longstanding interest within the software security…”
Get full text
Journal Article -
9
A Qualitative Study on Using ChatGPT for Software Security: Perception vs. Practicality
Published 01-08-2024“…Artificial Intelligence (AI) advancements have enabled the development of Large Language Models (LLMs) that can perform a variety of tasks with remarkable…”
Get full text
Journal Article -
10
Noisy Label Learning for Security Defects
Published 08-03-2022“…Data-driven software engineering processes, such as vulnerability prediction heavily rely on the quality of the data used. In this paper, we observe that it is…”
Get full text
Journal Article -
11
An Investigation into Inconsistency of Software Vulnerability Severity across Data Sources
Published 20-12-2021“…Software Vulnerability (SV) severity assessment is a vital task for informing SV remediation and triage. Ranking of SV severity scores is often used to advise…”
Get full text
Journal Article -
12
Data Preparation for Software Vulnerability Prediction: A Systematic Literature Review
Published 13-09-2021“…Software Vulnerability Prediction (SVP) is a data-driven technique for software quality assurance that has recently gained considerable attention in the…”
Get full text
Journal Article -
13
SmartValidator: A Framework for Automatic Identification and Classification of Cyber Threat Data
Published 14-03-2022“…A wide variety of Cyber Threat Information (CTI) is used by Security Operation Centres (SOCs) to perform validation of security incidents and alerts. Security…”
Get full text
Journal Article -
14
PUMiner: Mining Security Posts from Developer Question and Answer Websites with PU Learning
Published in 2020 IEEE/ACM 17th International Conference on Mining Software Repositories (MSR) (01-05-2020)“…Security is an increasing concern in software development. Developer Question and Answer (Q&A) websites provide a large amount of security discussion. Existing…”
Get full text
Conference Proceeding -
15
An Empirical Study of Rule-Based and Learning-Based Approaches for Static Application Security Testing
Published 05-07-2021“…Background: Static Application Security Testing (SAST) tools purport to assist developers in detecting security issues in source code. These tools typically…”
Get full text
Journal Article -
16
DeepCVA: Automated Commit-level Vulnerability Assessment with Deep Multi-task Learning
Published 18-08-2021“…It is increasingly suggested to identify Software Vulnerabilities (SVs) in code commits to give early warnings about potential security risks. However, there…”
Get full text
Journal Article -
17
An Empirical Study of Developers' Discussions about Security Challenges of Different Programming Languages
Published 28-07-2021“…Given programming languages can provide different types and levels of security support, it is critically important to consider security aspects while selecting…”
Get full text
Journal Article -
18
A Large-scale Study of Security Vulnerability Support on Developer Q&A Websites
Published 21-04-2021“…Context: Security Vulnerabilities (SVs) pose many serious threats to software systems. Developers usually seek solutions to addressing these SVs on developer…”
Get full text
Journal Article -
19
PUMiner: Mining Security Posts from Developer Question and Answer Websites with PU Learning
Published 08-03-2020“…Security is an increasing concern in software development. Developer Question and Answer (Q&A) websites provide a large amount of security discussion. Existing…”
Get full text
Journal Article