Skip to main content

Showing 1–1 of 1 results for author: Budde, I

.
  1. arXiv:2204.03089  [pdf, other

    cs.PL

    Fluently specifying taint-flow queries with fluentTQL

    Authors: Goran Piskachev, Johannes Späth, Ingo Budde, Eric Bodden

    Abstract: Previous work has shown that taint analyses are only useful if correctly customized to the context in which they are used. Existing domain-specific languages (DSLs) allow such customization through the definition of deny-listing data-flow rules that describe potentially vulnerable taint-flows. These languages, however, are designed primarily for security experts who are knowledgeable in taint anal… ▽ More

    Submitted 6 April, 2022; originally announced April 2022.

    Comments: 39 pages, Springer Journal on Empirical Software Engineering