{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,9]],"date-time":"2025-12-09T08:27:51Z","timestamp":1765268871086,"version":"3.40.3"},"publisher-location":"Cham","reference-count":41,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031280726"},{"type":"electronic","value":"9783031280733"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-28073-3_42","type":"book-chapter","created":{"date-parts":[[2023,3,1]],"date-time":"2023-03-01T06:04:47Z","timestamp":1677650687000},"page":"602-613","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Python Cryptographic Secure Scripting Concerns: A Study of Three Vulnerabilities"],"prefix":"10.1007","author":[{"given":"Grace","family":"LaMalva","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Suzanna","family":"Schmeelk","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dristi","family":"Dinesh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,3,2]]},"reference":[{"key":"42_CR1","unstructured":"Gulabovska, H., Porkolab, Z.: Survey on static analysis tools of python programs. http:\/\/ceur-ws.org\/Vol-2508\/paper-gul.pdf. Accessed 29 May 2022"},{"key":"42_CR2","doi-asserted-by":"crossref","unstructured":"McGraw, G., et al.: Static analysis for security. Institute of Electrical and Electronics Engineer (2004), vol. 2:6, pp. 76\u201379. https:\/\/ieeexplore.ieee.org\/abstract\/document\/1366126","DOI":"10.1109\/MSP.2004.111"},{"issue":"4","key":"42_CR3","doi-asserted-by":"publisher","first-page":"1384","DOI":"10.1109\/TR.2019.2937214","volume":"68","author":"A Braga","year":"2019","unstructured":"Braga, A., Dahab, R., Antunes, N., Laranjeiro, N., Vieira, M.: Understanding how to use static analysis tools for detecting cryptography misuse in software. IEEE Trans. Reliab. 68(4), 1384\u20131403 (2019). https:\/\/doi.org\/10.1109\/TR.2019.2937214","journal-title":"IEEE Trans. Reliab."},{"key":"42_CR4","unstructured":"Chess, B., West, J.: Secure Programming with Static Analysis. United States: Pearson Education (2007)"},{"key":"42_CR5","doi-asserted-by":"crossref","unstructured":"Gulabovska, H., Porkol\u00e1b, Z.: Evaluation of Static Analysis Methods of Python Programs. ipsitransactions, July 2020","DOI":"10.1109\/Informatics47936.2019.9119307"},{"key":"42_CR6","doi-asserted-by":"publisher","unstructured":"Dong, T., Chen, L., Xu, Z., Yu, B.: Static type analysis for python. In: 2014 11th Web Information System and Application Conference, pp. 65\u201368 (2014). https:\/\/doi.org\/10.1109\/WISA.2014.20","DOI":"10.1109\/WISA.2014.20"},{"issue":"05","key":"42_CR7","doi-asserted-by":"publisher","first-page":"10","DOI":"10.1109\/MITP.2005.120","volume":"7","author":"G Lindstrom","year":"2005","unstructured":"Lindstrom, G.: Programming with python. IT Professional 7(05), 10\u201316 (2005)","journal-title":"IT Professional"},{"key":"42_CR8","doi-asserted-by":"crossref","unstructured":"P.T.G.H. Inc., P. Thomson, G. H. Inc., G. H. I. V. Profile, and O. M. V. A. Metrics: Static Analysis: An introduction: The fundamental challenge of software engineering is one of Complexity. Queue, vol. 19, no 4, Queue. https:\/\/dl.acm.org\/doi\/10.1145\/3487019.3487021. Accessed 28 May 2022","DOI":"10.1145\/3487019.3487021"},{"key":"42_CR9","unstructured":"Ferrer, F., More, A.: Towards secure scripting development. Argentina Software Development Center, vol. 1, pp. 42\u201353 (2011). https:\/\/40jaiio.sadio.org.ar\/sites\/default\/files\/T2011\/WSegI\/972.pdf"},{"key":"42_CR10","doi-asserted-by":"crossref","unstructured":"Nielson, J., Monson, C.: Practical Cryptography in Python: Learning Correct Cryptography by Example, 1st edn. Apress (2019)","DOI":"10.1007\/978-1-4842-4900-0_1"},{"key":"42_CR11","doi-asserted-by":"publisher","unstructured":"Qadir, A.M., Varol, N.: A review paper on cryptography. In: 2019 7th International Symposium on Digital Forensics and Security (ISDFS), pp. 1\u20136 (2019). https:\/\/doi.org\/10.1109\/ISDFS.2019.8757514.URL:\u00a0https:\/\/ieeexplore.ieee.org\/stamp\/stamp.jsp?tp=&arnumber=8757514&isnumber=8757466","DOI":"10.1109\/ISDFS.2019.8757514.URL"},{"key":"42_CR12","unstructured":"Kessler, G.C.: An overview of cryptography - princeton university. https:\/\/www.cs.princeton.edu\/~chazelle\/courses\/BIB\/overview-crypto.pdf. Accessed 29 May 2022"},{"key":"42_CR13","unstructured":"Mundt, M., Baier, H.: Towards mitigation of data exfiltration techniques using the MITRE ATT&CK framework. Research Institute CODE, Universit\u00e4t der Bundeswehr M\u00fcnchen, Germany, vol. 1 pp. 1\u201322 (2021). https:\/\/www.unibw.de\/digfor\/publikationen\/pdf\/2021-12-icdf2c-mundt-baier.pdf"},{"key":"42_CR14","unstructured":"Algoma. https:\/\/archives.algomau.ca\/main\/sites\/default\/files\/2012-25_001_011.pdf. Accessed 28 May 2022"},{"key":"42_CR15","doi-asserted-by":"crossref","unstructured":"Devi, S.V., Kotha, H.D.:\u2009Journal of Physics: Conference Series; Bristol, vol. 1228, Iss. 1, May 2019","DOI":"10.1088\/1742-6596\/1228\/1\/012006"},{"key":"42_CR16","unstructured":"Contrast-security-OSS\/VULNPY: Purposely-vulnerable python functions. GitHub. https:\/\/github.com\/Contrast-Security-OSS\/vulnpy. Accessed 28 May 2022"},{"key":"42_CR17","unstructured":"Fportantier, Fportantier\/vulpy: Vulnerable python application to learn secure development. GitHub, 14 Sep 2020. https:\/\/github.com\/fportantier\/vulpy. Accessed 28 May 2022"},{"key":"42_CR18","unstructured":"Jorritfolmer\/vulnerable-API: Enhanced Fork with logging, openapi 3.0 and Python 3 for Security Monitoring Workshops. GitHub. https:\/\/github.com\/jorritfolmer\/vulnerable-api. Accessed 28 May 2022"},{"key":"42_CR19","unstructured":"sgabe\/DSVPWA: Damn simple vulnerable python web application. GitHub. https:\/\/github.com\/sgabe\/DSVPWA. Accessed 28 May 2022"},{"key":"42_CR20","unstructured":"Random - generate pseudo-random numbers. random - Generate pseudo-random numbers - Python 3.10.5 documentation. https:\/\/docs.python.org\/3\/library\/random.html. Accessed 27 May 2022"},{"key":"42_CR21","unstructured":"Secrets - generate secure random numbers for managing secrets. secrets - Generate secure random numbers for managing secrets - Python 3.10.5 documentation. https:\/\/docs.python.org\/3\/library\/secrets.html#module-secrets. Accessed 27 May 2022"},{"key":"42_CR22","doi-asserted-by":"publisher","unstructured":"Braga, A., Dahab, R., Antunes, N., Laranjeiro, N., Vieira, M.: Practical evaluation of static analysis tools for cryptography: benchmarking method and case study. In: 2017 IEEE 28th International Symposium on Software Reliability Engineering (ISSRE), pp. 170\u2013181 (2017). https:\/\/doi.org\/10.1109\/ISSRE.2017.27","DOI":"10.1109\/ISSRE.2017.27"},{"key":"42_CR23","doi-asserted-by":"crossref","unstructured":"Wickert, A.-K., et al.: Python crypto misuses in the wild. In: ESEM Conference Bari, Italy (2021), vol. 1, pp. 1\u20136. https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3475716.3484195","DOI":"10.1145\/3475716.3484195"},{"key":"42_CR24","doi-asserted-by":"publisher","unstructured":"Schmeelk, S., Tao, L.: A case study of mobile health applications: the OWASP risk of insufficient cryptography. J. Comput. Sci. Res. [S.l.] 4(1) (2022). ISSN 2630-5151. https:\/\/ojs.bilpublishing.com\/index.php\/jcsr\/article\/view\/4271. Accessed 28 May 2022. https:\/\/doi.org\/10.30564\/jcsr.v4i1.4271","DOI":"10.30564\/jcsr.v4i1.4271"},{"key":"42_CR25","doi-asserted-by":"publisher","unstructured":"Rahaman, S., et al.: Cryptoguard. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (2019). https:\/\/doi.org\/10.1145\/3319535.3345659","DOI":"10.1145\/3319535.3345659"},{"key":"42_CR26","doi-asserted-by":"crossref","unstructured":"Acar, Y., Stransky, C., Wermke, D., Weir, C., Mazurek, M.L., Fahl, S.: Developers need support, too: a survey of security advice for software developers. In: 2017 IEEE Cybersecurity Development (SecDev) (2017)","DOI":"10.1109\/SecDev.2017.17"},{"key":"42_CR27","doi-asserted-by":"publisher","unstructured":"Muske, T., Khedker, U.P.: Efficient elimination of false positives using static analysis. In: 2015 IEEE 26th International Symposium on Software Reliability Engineering (ISSRE), pp. 270\u2013280 (2015). https:\/\/doi.org\/10.1109\/ISSRE.2015.7381820","DOI":"10.1109\/ISSRE.2015.7381820"},{"key":"42_CR28","doi-asserted-by":"publisher","unstructured":"Thung, F., Lucia, Lo, D., Jiang, L., Rahman, F., Devanbu, P.T.: To what extent could we detect field defects? an empirical study of false negatives in static bug finding tools. In: 2012 Proceedings of the 27th IEEE\/ACM International Conference on Automated Software Engineering, pp. 50\u201359 (2012). https:\/\/doi.org\/10.1145\/2351676.2351685","DOI":"10.1145\/2351676.2351685"},{"key":"42_CR29","doi-asserted-by":"publisher","unstructured":"Chess, B., McGraw, G.: Static analysis for security. IEEE Secur. Privacy 2(6), 76\u201379 (2004). https:\/\/doi.org\/10.1109\/MSP.2004.111","DOI":"10.1109\/MSP.2004.111"},{"key":"42_CR30","unstructured":"Sphinx-Quickstart: Prospector - python static analysis. Webpage (2014). \u200b\u200bhttps:\/\/prospector.landscape.io\/en\/master\/index.html"},{"key":"42_CR31","unstructured":"Brown, E.: PyCQA - Bandit. GitHub (2022). https:\/\/github.com\/PyCQA\/bandit"},{"key":"42_CR32","unstructured":"Luminousmen. \u201cPython static analysis tools.\u201d Webpage (2021). https:\/\/luminousmen.com\/post\/python-static-analysis-tools"},{"key":"42_CR33","doi-asserted-by":"crossref","unstructured":"Ruohonen, J., Hjerppe, K., Rindell, K.: A large-scale security-oriented static analysis of python packages in PyPI.  University of Turku, Finland, vol. 1, pp. 1\u201310 (2021)","DOI":"10.1109\/PST52912.2021.9647791"},{"key":"42_CR34","unstructured":"Github: GitHub. https:\/\/github.com\/. Accessed 28 May 2022"},{"key":"42_CR35","unstructured":"Local Coder: Python: ignore \u2018incorrect padding\u2019 error when base64 decoding. Webpage (2022). https:\/\/localcoder.org\/python-ignore-incorrect-padding-error-when-base64-decoding"},{"key":"42_CR36","unstructured":"Projects: Linux Foundation, 28 June 2022. https:\/\/www.linuxfoundation.org\/projects\/. Accessed 30 June 2022"},{"key":"42_CR37","doi-asserted-by":"publisher","unstructured":"Kannavara, R.: Securing opensource code via static analysis. In: 2012 IEEE Fifth International Conference on Software Testing, Verification and Validation, pp. 429\u2013436 (2012). https:\/\/doi.org\/10.1109\/ICST.2012.123","DOI":"10.1109\/ICST.2012.123"},{"key":"42_CR38","unstructured":"M2: Insecure data storage: M2: Insecure Data Storage | OWASP Foundation. https:\/\/owasp.org\/www-project-mobile-top-10\/2016-risks\/m2-insecure-data-storage. Accessed 28 May 2022"},{"key":"42_CR39","unstructured":"Enforcing security for temporary files. SpringerLink, 01 Jan 1970. https:\/\/link.springer.com\/chapter\/10.1007\/978-1-4302-0057-4_15?noAccess=true#citeas. Accessed 28 May 2022"},{"key":"42_CR40","unstructured":"IBM explores the future of Cryptography: IBM Newsroom. https:\/\/newsroom.ibm.com\/IBM-Explores-the-Future-of-Cryptography"},{"key":"42_CR41","doi-asserted-by":"publisher","unstructured":"Chen, Z., Chen, L., Zhou, Y., Xu, Z., Chu, W.C., Xu, B.: Dynamic slicing of python programs. In: 2014 IEEE 38th Annual Computer Software and Applications Conference (2014). https:\/\/doi.org\/10.1109\/compsac.2014.30","DOI":"10.1109\/compsac.2014.30"}],"container-title":["Lecture Notes in Networks and Systems","Advances in Information and Communication"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-28073-3_42","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,3,1]],"date-time":"2023-03-01T06:12:46Z","timestamp":1677651166000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-28073-3_42"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031280726","9783031280733"],"references-count":41,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-28073-3_42","relation":{},"ISSN":["2367-3370","2367-3389"],"issn-type":[{"type":"print","value":"2367-3370"},{"type":"electronic","value":"2367-3389"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"2 March 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"FICC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Future of Information and Communication Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"San Francisco, CA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2 March 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3 March 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ficc2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}