{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,14]],"date-time":"2026-02-14T04:34:05Z","timestamp":1771043645304,"version":"3.50.1"},"publisher-location":"Cham","reference-count":38,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783031094835","type":"print"},{"value":"9783031094842","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-09484-2_6","type":"book-chapter","created":{"date-parts":[[2022,6,24]],"date-time":"2022-06-24T14:02:51Z","timestamp":1656079371000},"page":"96-115","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["VANDALIR: Vulnerability Analyses Based on\u00a0Datalog and\u00a0LLVM-IR"],"prefix":"10.1007","author":[{"given":"Joschua","family":"Schilling","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tilo","family":"M\u00fcller","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,6,24]]},"reference":[{"key":"6_CR1","unstructured":"Andersen, L.O.: Program analysis and specialization for the C programming language. Ph.D. thesis, Citeseer (1994)"},{"key":"6_CR2","doi-asserted-by":"crossref","unstructured":"Antoniadis, T., Triantafyllou, K., Smaragdakis, Y.: Porting doop to souffl\u00e9: a tale of inter-engine portability for datalog-based analyses. In: Proceedings of the 6th ACM SIGPLAN International Workshop on State Of the Art in Program Analysis, pp. 25\u201330 (2017)","DOI":"10.1145\/3088515.3088522"},{"key":"6_CR3","doi-asserted-by":"crossref","unstructured":"Arusoaie, A., Ciob\u00e2ca, S., Craciun, V., Gavrilut, D., Lucanu, D.: A comparison of open-source static analysis tools for vulnerability detection in c\/c++ code. In: 2017 19th International Symposium on Symbolic and Numeric Algorithms for Scientific Computing (SYNASC), pp. 161\u2013168. IEEE (2017)","DOI":"10.1109\/SYNASC.2017.00035"},{"key":"6_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"84","DOI":"10.1007\/978-3-662-53413-7_5","volume-title":"Static Analysis","author":"G Balatsouras","year":"2016","unstructured":"Balatsouras, G., Smaragdakis, Y.: Structure-sensitive points-to analysis for C and C++. In: Rival, X. (ed.) SAS 2016. LNCS, vol. 9837, pp. 84\u2013104. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-53413-7_5"},{"key":"6_CR5","doi-asserted-by":"crossref","unstructured":"Criswell, J., Johnson, E., Pronovost, C.: Tutorial: Llvm for security practitioners. In: IEEE Secure Development Conference (2020)","DOI":"10.1109\/SecDev45635.2020.00013"},{"key":"6_CR6","unstructured":"Dhir, A.: Open TFTP Server - Project Website (2019). https:\/\/sourceforge.net\/projects\/tftp-server\/, Accessed 22 May 2021"},{"key":"6_CR7","unstructured":"Dillig, I., Dillig, T., Aiken, A.: Sail: static analysis intermediate language with a two-level representation. Technical report (2009)"},{"key":"6_CR8","doi-asserted-by":"crossref","unstructured":"Gao, Y., Chen, L., Shi, G., Zhang, F.: A comprehensive detection of memory corruption vulnerabilities for c\/c++ programs. In: 2018 IEEE International Conference on Parallel & Distributed Processing with Applications, Ubiquitous Computing & Communications, Big Data & Cloud Computing, Social Computing & Networking, Sustainable Computing & Communications (ISPA\/IUCC\/BDCloud\/SocialCom\/SustainCom), pp. 354\u2013360. IEEE (2018)","DOI":"10.1109\/BDCloud.2018.00062"},{"key":"6_CR9","unstructured":"Garmany, B.: Mentalese-an architecture-agnostic analysis framework for binary executables (2021)"},{"key":"6_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"68","DOI":"10.1007\/978-3-030-29962-0_4","volume-title":"Computer Security \u2013 ESORICS 2019","author":"B Garmany","year":"2019","unstructured":"Garmany, B., Stoffel, M., Gawlik, R., Holz, T.: Static detection of uninitialized stack variables in binary code. In: Sako, K., Schneider, S., Ryan, P.Y.A. (eds.) ESORICS 2019. LNCS, vol. 11736, pp. 68\u201387. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-29962-0_4"},{"key":"6_CR11","volume-title":"Datalog and Recursive Query Processing","author":"TJ Green","year":"2013","unstructured":"Green, T.J., Huang, S.S., Loo, B.T., Zhou, W., et al.: Datalog and Recursive Query Processing. Now Publishers, Norwell (2013)"},{"key":"6_CR12","unstructured":"Jain, A.: CVE-2021-3156: heap-based buffer overflow in sudo (baron samedit) (2021). https:\/\/blog.qualys.com\/vulnerabilities-threat-research\/2021\/01\/26\/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit, Accessed 21 Apr 2021"},{"key":"6_CR13","doi-asserted-by":"publisher","first-page":"2023","DOI":"10.1016\/j.procs.2020.04.217","volume":"171","author":"A Kaur","year":"2020","unstructured":"Kaur, A., Nayyar, R.: A comparative study of static code analysis tools for vulnerability detection in c\/c++ and java source code. Procedia Comput. Sci. 171, 2023\u20132029 (2020)","journal-title":"Procedia Comput. Sci."},{"key":"6_CR14","doi-asserted-by":"publisher","first-page":"523","DOI":"10.1016\/B978-0-444-51624-4.50012-5","volume":"9","author":"RA Kowalski","year":"2014","unstructured":"Kowalski, R.A.: Logic programming. Comput. Logic 9, 523\u2013569 (2014)","journal-title":"Comput. Logic"},{"key":"6_CR15","unstructured":"Lattner, C.: Llvm. In: Brown, A., Wilson, G. (eds.) The Architecture of Open Source Applications: Elegance, Evolution, and a Few Fearless Hacks, vol. 1. Lulu. com (2011)"},{"key":"6_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"78","DOI":"10.1007\/978-3-642-24206-9_5","volume-title":"Datalog Reloaded","author":"V Lifschitz","year":"2011","unstructured":"Lifschitz, V.: Datalog programs and their stable models. In: de Moor, O., Gottlob, G., Furche, T., Sellers, A. (eds.) Datalog 2.0 2010. LNCS, vol. 6702, pp. 78\u201387. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-24206-9_5"},{"key":"6_CR17","unstructured":"Marjam\u00e4ki, D.: Cppcheck - a tool for static C\/C++ code analysis (2021). http:\/\/cppcheck.sourceforge.net\/, Accessed 17 July 2021"},{"key":"6_CR18","unstructured":"Miller, T.C.: Buffer overflow in command line unescaping (2021). Accessed 12 Mar 2021"},{"key":"6_CR19","unstructured":"Mishra, D.: GattLib 0.2 - stack buffer overflow. https:\/\/www.exploit-db.com\/exploits\/46215, Accessed 21 June 2021"},{"key":"6_CR20","unstructured":"Open Source Software of Telefonaktiebolaget LM Ericsson: CodeChecker Website (2021). https:\/\/codechecker.readthedocs.io\/en\/latest\/, Accessed 17 July 2021"},{"key":"6_CR21","unstructured":"Part, L.A.: GattLib - GitHub repository. Lab A Part. https:\/\/github.com\/labapart\/gattlib, Accessed 21 June 2021"},{"key":"6_CR22","unstructured":"Project, L.: LLVM Language Reference Manual - LLVM 12 documentation. LLVM Project (2021). https:\/\/llvm.org\/docs\/LangRef.html, Accessed 21 Jan 2021"},{"key":"6_CR23","unstructured":"Project, S.: Souffl\u00e9. A Datalog Synthesis Tool for Static Analysis. Souffl\u00e9 Project. https:\/\/souffle-lang.github.io\/, Accessed 22 Jan 2021"},{"key":"6_CR24","unstructured":"llvmlite Project, T.: A Lightweight LLVM Python Binding for Writing JIT Compilers - GitHub repository. The llvmlite Project. https:\/\/github.com\/numba\/llvmlite, Accessed 07 Feb 2021"},{"key":"6_CR25","unstructured":"Project, T.C.: Clang Static Analyzer. The Clang Project (2021). https:\/\/clang-analyzer.llvm.org\/, Accessed 17 July 2021"},{"key":"6_CR26","unstructured":"Project, T.C.: Clang-Tidy. The Clang Project (2021). https:\/\/clang.llvm.org\/extra\/clang-tidy\/, Accessed 17 July 2021"},{"key":"6_CR27","unstructured":"Psallida, E.I., Balatsouras, G.: Relational representation of the LLVM intermediate language. Ph.D. thesis, BS Thesis, University of Athens (2014)"},{"key":"6_CR28","doi-asserted-by":"publisher","unstructured":"Russell, R., et al.: Automated vulnerability detection in source code using deep representation learning. In: 2018 17th IEEE International Conference on Machine Learning and Applications (ICMLA), pp. 757\u2013762 (2018). https:\/\/doi.org\/10.1109\/ICMLA.2018.00120","DOI":"10.1109\/ICMLA.2018.00120"},{"key":"6_CR29","doi-asserted-by":"crossref","unstructured":"Scholz, B., Jordan, H., Suboti\u0107, P., Westmann, T.: On fast large-scale program analysis in datalog. In: Proceedings of the 25th International Conference on Compiler Construction, pp. 196\u2013206 (2016)","DOI":"10.1145\/2892208.2892226"},{"key":"6_CR30","doi-asserted-by":"crossref","unstructured":"Schubert, P.D., Hermann, B., Bodden, E.: Phasar: an inter-procedural static analysis framework for c\/c++. In: TACAS, vol. 2, pp. 393\u2013410 (2019)","DOI":"10.1007\/978-3-030-17465-1_22"},{"key":"6_CR31","doi-asserted-by":"publisher","unstructured":"Shiraishi, S., Mohan, V., Marimuthu, H.: Test suites for benchmarks of static analysis tools. In: 2015 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW), pp. 12\u201315 (2015). https:\/\/doi.org\/10.1109\/ISSREW.2015.7392027","DOI":"10.1109\/ISSREW.2015.7392027"},{"key":"6_CR32","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"245","DOI":"10.1007\/978-3-642-24206-9_14","volume-title":"Datalog Reloaded","author":"Y Smaragdakis","year":"2011","unstructured":"Smaragdakis, Y., Bravenboer, M.: Using datalog for fast and easy program analysis. In: de Moor, O., Gottlob, G., Furche, T., Sellers, A. (eds.) Datalog 2.0 2010. LNCS, vol. 6702, pp. 245\u2013251. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-24206-9_14"},{"key":"6_CR33","unstructured":"St Amour, L.: Interactive synthesis of code level security rules. Northeastern University Boston United States, Technical report (2017)"},{"key":"6_CR34","unstructured":"N.I., Technology of Standards: Juliet Test Suite v1.2for C\/C++User Guide. National Institute of Standards and Technology (2012). Accessed 12 June 2021"},{"key":"6_CR35","doi-asserted-by":"crossref","unstructured":"Sui, Y., Xue, J.: SVF: interprocedural static value-flow analysis in llvm. In: Proceedings of the 25th International Conference on Compiler Construction, pp. 265\u2013266 (2016)","DOI":"10.1145\/2892208.2892235"},{"key":"6_CR36","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"316","DOI":"10.1007\/978-3-030-03427-6_24","volume-title":"Leveraging Applications of Formal Methods, Verification and Validation. Industrial Practice","author":"P Tsankov","year":"2018","unstructured":"Tsankov, P.: Security analysis of smart contracts in datalog. In: Margaria, T., Steffen, B. (eds.) ISoLA 2018. LNCS, vol. 11247, pp. 316\u2013322. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-03427-6_24"},{"key":"6_CR37","doi-asserted-by":"crossref","unstructured":"Wagner, A., Sametinger, J.: Using the juliet test suite to compare static security scanners. In: 2014 11th International Conference on Security and Cryptography (SECRYPT), pp. 1\u20139. IEEE (2014)","DOI":"10.5220\/0005032902440252"},{"key":"6_CR38","unstructured":"Wheeler, D.A.: Flawfinder - Project Website (2021). https:\/\/dwheeler.com\/flawfinder\/, Accessed 17 July 2021"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-09484-2_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,24]],"date-time":"2022-06-24T14:04:15Z","timestamp":1656079455000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-09484-2_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031094835","9783031094842"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-09484-2_6","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"24 June 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DIMVA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Cagliari","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 June 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"1 July 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dimva2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/sites.unica.it\/dimva2022\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"HotCRP","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"39","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"10","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"26% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2.1","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}