{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T07:19:32Z","timestamp":1740122372248,"version":"3.37.3"},"reference-count":63,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2022,5,30]],"date-time":"2022-05-30T00:00:00Z","timestamp":1653868800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,5,30]],"date-time":"2022-05-30T00:00:00Z","timestamp":1653868800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100008530","name":"European Regional Development Fund","doi-asserted-by":"publisher","award":["ERDF-0801379"],"award-info":[{"award-number":["ERDF-0801379"]}],"id":[{"id":"10.13039\/501100008530","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Fraunhofer-Institut f\u00fcr Entwurfstechnik Mechatronik IEM"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2022,9]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Previous work has shown that taint analyses are only useful if correctly customized to the context in which they are used. Existing domain-specific languages (DSLs) allow such customization through the definition of deny-listing data-flow rules that describe potentially vulnerable or malicious taint-flows. These languages, however, are designed primarily for security experts who are expected to be knowledgeable in taint analysis. Software developers, however, consider these languages to be complex. This paper thus presents <jats:italic><jats:sc>fluent<\/jats:sc><\/jats:italic> TQL, a query specification language particularly for taint-flows. <jats:italic><jats:sc>fluent<\/jats:sc><\/jats:italic>TQL is internal Java DSL and uses a fluent-interface design. <jats:italic><jats:sc>fluent<\/jats:sc><\/jats:italic>TQL queries can express various taint-style vulnerability types, e.g. injections, cross-site scripting or path traversal. This paper describes <jats:italic><jats:sc>fluent<\/jats:sc><\/jats:italic>TQL\u2019s abstract and concrete syntax and defines its runtime semantics. The semantics are independent of any underlying analysis and allows evaluation of <jats:italic><jats:sc>fluent TQL<\/jats:sc><\/jats:italic> queries by a variety of taint analyses. Instantiations of <jats:italic><jats:sc>fluent<\/jats:sc><\/jats:italic>TQL, on top of two taint analysis solvers, Boomerang and FlowDroid, show and validate <jats:italic><jats:sc>fluent<\/jats:sc><\/jats:italic> TQL expressiveness. Based on existing examples from the literature, we have used <jats:italic><jats:sc>fluent<\/jats:sc><\/jats:italic>TQL to implement queries for 11 popular security vulnerability types in Java. Using our SQL injection specification, the Boomerang-based taint analysis found all 17 known taint-flows in the OWASP WebGoat application, whereas with FlowDroid 13 taint-flows were found. Similarly, in a vulnerable version of the Java Spring PetClinic application, the Boomerang-based taint analysis found all seven expected taint-flows. In seven real-world Android apps with 25 expected malicious taint-flows, 18 taint-flows were detected. In a user study with 26 software developers, <jats:italic><jats:sc>fluent<\/jats:sc><\/jats:italic>TQL reached a high usability score. In comparison to <jats:sc>CodeQL<\/jats:sc>, the state-of-the-art DSL by Semmle\/GitHub, participants found <jats:italic><jats:sc>fluent<\/jats:sc><\/jats:italic>TQL more usable and with it they were able to specify taint analysis queries in shorter time.<\/jats:p>","DOI":"10.1007\/s10664-022-10165-y","type":"journal-article","created":{"date-parts":[[2022,5,30]],"date-time":"2022-05-30T09:03:03Z","timestamp":1653901383000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Fluently specifying taint-flow queries with fluentTQL"],"prefix":"10.1007","volume":"27","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4424-5838","authenticated-orcid":false,"given":"Goran","family":"Piskachev","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4462-9372","authenticated-orcid":false,"given":"Johannes","family":"Sp\u00e4th","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0124-6291","authenticated-orcid":false,"given":"Ingo","family":"Budde","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3470-3647","authenticated-orcid":false,"given":"Eric","family":"Bodden","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,5,30]]},"reference":[{"key":"10165_CR1","doi-asserted-by":"publisher","unstructured":"Antoniadis A, Filippakis N, Krishnan P, Ramesh R, Allen N, Smaragdakis Y (2020) Static analysis of java enterprise applications: frameworks and caches, the elephants in the room. In: Proceedings of the 41st ACM SIGPLAN conference on programming language design and implementation, PLDI 2020. https:\/\/doi.org\/10.1145\/3385412.3386026. ACM, New York, pp 794\u2013807","DOI":"10.1145\/3385412.3386026"},{"key":"10165_CR2","unstructured":"Arzt S, Rasthofer S, Bodden E (2013) Susi: a tool for the fully automated classification and categorization of android sources and sinks. In: Network and distributed system security symposium 2013, NDSS\u201913"},{"key":"10165_CR3","doi-asserted-by":"crossref","unstructured":"Arzt S, Rasthofer S, Fritz C, Bodden E, Bartel A, Klein J, Traon Y L, Octeau D, McDaniel P (2014) Flowdroid: precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for android apps. In: Proceedings of the 35th ACM SIGPLAN conference on programming language design and implementation, PLDI \u201914. ACM, New York, pp 259\u2013269","DOI":"10.1145\/2594291.2594299"},{"key":"10165_CR4","doi-asserted-by":"crossref","unstructured":"Bodden E (2018) The secret sauce in efficient and precise static analysis: the beauty of distributive, summary-based static analyses (and how to master them). In: ACM SIGPLAN International workshop on the state of the art in java program analysis (SOAP 2018), ISSTA \u201918. ACM, New York, pp 85\u201393","DOI":"10.1145\/3236454.3236500"},{"issue":"2","key":"10165_CR5","first-page":"29","volume":"8","author":"J Brooke","year":"2013","unstructured":"Brooke J (2013) Sus: a retrospective. J Usability Stud 8(2):29\u201340","journal-title":"J Usability Stud"},{"key":"10165_CR6","unstructured":"Checkmarx (2020) Checkmarx. https:\/\/www.checkmarx.com\/, online; accessed January 2021"},{"key":"10165_CR7","doi-asserted-by":"crossref","unstructured":"Chibotaru V, Bichsel B, Raychev V, Vechev M (2019) Scalable taint specification inference with big code. In: Proceedings of the 40th ACM SIGPLAN conference on programming language design and implementation, PLDI 2019. ACM, New York, pp 760\u2013774","DOI":"10.1145\/3314221.3314648"},{"key":"10165_CR8","doi-asserted-by":"crossref","unstructured":"Christakis M, Bird C (2016) What developers want and need from program analysis: an empirical study. In: Proceedings of the 31st IEEE\/ACM international conference on automated software engineering, ASE 2016. ACM, New York, pp 332\u2013343","DOI":"10.1145\/2970276.2970347"},{"key":"10165_CR9","volume-title":"Quasi-experimentation: design and analysis issues for field settings","author":"TD Cook","year":"1979","unstructured":"Cook T D, Campbell D T (1979) Quasi-experimentation: design and analysis issues for field settings. Houghton Mifflin, Boston"},{"key":"10165_CR10","doi-asserted-by":"crossref","unstructured":"Dietl W, Dietzel S, Ernst M D, Mu\u015flu K, Schiller T W (2011) Building and using pluggable type-checkers. In: Proceedings of the 33rd international conference on software engineering, ICSE11. ACM, New York, pp 681\u2013690","DOI":"10.1145\/1985793.1985889"},{"key":"10165_CR11","doi-asserted-by":"crossref","unstructured":"Feng Y, Anand S, Dillig I, Aiken A (2014) Apposcopy: semantics-based detection of android malware through static analysis. In: Proceedings of the 22nd ACM SIGSOFT international symposium on foundations of software engineering, FSE 2014. ACM, New York, pp 576\u2013587","DOI":"10.1145\/2635868.2635869"},{"key":"10165_CR12","doi-asserted-by":"crossref","unstructured":"Girden ER (1992) ANOVA: repeated measures. 84, Sage","DOI":"10.4135\/9781412983419"},{"key":"10165_CR13","unstructured":"Github S (2020) Lgtm. http:\/\/lgtm.com\/, online; accessed January 2021"},{"key":"10165_CR14","doi-asserted-by":"crossref","unstructured":"Gordon M I, Kim D, Perkins J H, Gilham L, Nguyen N, Rinard M C (2015) Information flow analysis of android applications in droidsafe. In: 22nd Annual network and distributed system security symposium, NDSS 2015, San Diego, California, USA, February 8\u201311, 2015. The Internet Society","DOI":"10.14722\/ndss.2015.23089"},{"key":"10165_CR15","doi-asserted-by":"crossref","unstructured":"Gotovchits I, van Tonder R, Brumley D (2018) Saluki: finding taint-style vulnerabilities with static property checking. In: Proceedings of the NDSS Workshop on Binary Analysis Research","DOI":"10.14722\/bar.2018.23019"},{"key":"10165_CR16","unstructured":"Grammatech (2020) Codesonar. https:\/\/www.grammatech.com\/products\/codesonar, online; accessed January 2021"},{"key":"10165_CR17","doi-asserted-by":"crossref","unstructured":"Grech N, Fourtounis G, Francalanza A, Smaragdakis Y (2018) Shooting from the heap: ultra-scalable static analysis with heap snapshots. In: Proceedings of the 27th ACM SIGSOFT international symposium on software testing and analysis, ISSTA 2018. ACM, New York, pp 198\u2013208","DOI":"10.1145\/3213846.3213860"},{"key":"10165_CR18","doi-asserted-by":"crossref","unstructured":"Johnson B, Song Y, Murphy-Hill E, Bowdidge R (2013) Why don\u2019t software developers use static analysis tools to find bugs?. In: Proceedings of the international conference on software engineering, ICSE \u201913. IEEE Press, Piscataway, pp 672\u2013681","DOI":"10.1109\/ICSE.2013.6606613"},{"issue":"6","key":"10165_CR19","doi-asserted-by":"publisher","first-page":"291","DOI":"10.1145\/2813885.2737957","volume":"50","author":"A Johnson","year":"2015","unstructured":"Johnson A, Waye L, Moore S, Chong S (2015) Exploring and enforcing security guarantees via program dependence graphs. SIGPLAN Not 50 (6):291\u2013302","journal-title":"SIGPLAN Not"},{"key":"10165_CR20","unstructured":"Kr\u00fcger S, Sp\u00e4th J, Ali K, Bodden E, Mezini M (2019) Crysl: an extensible approach to validating the correct usage of cryptographic apis. IEEE Trans Softw Eng"},{"key":"10165_CR21","doi-asserted-by":"crossref","unstructured":"Le W, Soffa M L (2011) Generating analyses for detecting faults in path segments. In: Proceedings of the 2011 international symposium on software testing and analysis, ISSTA11. ACM, New York, pp 320\u2013330","DOI":"10.1145\/2001420.2001459"},{"key":"10165_CR22","unstructured":"Livshits B (2012) Dynamic taint tracking in managed runtimes. Tech. rep., Microsoft Research"},{"issue":"6","key":"10165_CR23","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1145\/1543135.1542485","volume":"44","author":"B Livshits","year":"2009","unstructured":"Livshits B, Nori A V, Rajamani S K, Banerjee A (2009) Merlin: specification inference for explicit information flow problems. SIGPLAN Not 44(6):75\u201386","journal-title":"SIGPLAN Not"},{"key":"10165_CR24","doi-asserted-by":"publisher","unstructured":"Luo L, Dolby J, Bodden E (2019) Magpiebridge: a general approach to integrating static analyses into IDEs and editors (tool insights paper). In: Donaldson AF (ed) 33rd European conference on object-oriented programming (ECOOP 2019), Schloss Dagstuhl\u2013Leibniz-Zentrum fuer informatik, Dagstuhl, Germany, vol 134. https:\/\/doi.org\/10.4230\/LIPIcs.ECOOP.2019.21, pp 21:1\u201321:25","DOI":"10.4230\/LIPIcs.ECOOP.2019.21"},{"key":"10165_CR25","doi-asserted-by":"crossref","unstructured":"Luo L, Pauck F, Piskachev G, Benz M, Pashchenko I, Mory M, Bodden E, Hermann B, Massacci F (2021) Taintbench: automatic real-world malware benchmarking of android taint analyses. Empir Softw Eng","DOI":"10.1007\/s10664-021-10013-5"},{"issue":"10","key":"10165_CR26","doi-asserted-by":"publisher","first-page":"365","DOI":"10.1145\/1103845.1094840","volume":"40","author":"M Martin","year":"2005","unstructured":"Martin M, Livshits B, Lam M S (2005) Finding application errors and security flaws using pql: a program query language. SIGPLAN Not 40(10):365\u2013383","journal-title":"SIGPLAN Not"},{"key":"10165_CR27","unstructured":"Microfocus (2020) Fortify. https:\/\/www.microfocus.com\/en-us\/products\/static-code-analysis-sast\/overview, online; accessed January 2021"},{"key":"10165_CR28","unstructured":"Microsoft (2020) Language server protocol. https:\/\/microsoft.github.io\/language-server-protocol\/, online; accessed January 2021"},{"key":"10165_CR29","unstructured":"Mitre CWE (2020a) 2011 cwe\/sans top 25 most dangerous software errors. http:\/\/cwe.mitre.org\/top25\/, online; accessed January 2021"},{"key":"10165_CR30","unstructured":"Mitre CWE (2020b) Cwe home page. http:\/\/cwe.mitre.org\/, online; accessed January 2021"},{"key":"10165_CR31","unstructured":"Mitre CWE (2020c) Improper neutralization of data within xpath expressions. https:\/\/cwe.mitre.org\/data\/definitions\/643.html, online; accessed January 2021"},{"key":"10165_CR32","unstructured":"Mitre CWE (2020d) Improper neutralization of input during web page generation. https:\/\/cwe.mitre.org\/data\/definitions\/79.html, online; accessed January 2021"},{"key":"10165_CR33","unstructured":"Mitre CWE (2020e) Improper neutralization of special elements in data query logic. https:\/\/cwe.mitre.org\/data\/definitions\/943.html, online; accessed January 2021"},{"key":"10165_CR34","unstructured":"Mitre CWE (2020f) Improper neutralization of special elements used in a command. https:\/\/cwe.mitre.org\/data\/definitions\/77.html, online; accessed January 2021"},{"key":"10165_CR35","unstructured":"Mitre CWE (2020g) Improper neutralization of special elements used in an ldap query. https:\/\/cwe.mitre.org\/data\/definitions\/90.html, online; accessed January 2021"},{"key":"10165_CR36","unstructured":"Mitre CWE (2020h) Improper neutralization of special elements used in an sql command. https:\/\/cwe.mitre.org\/data\/definitions\/89.html, online; accessed January 2021"},{"key":"10165_CR37","unstructured":"Mitre CWE (2020i) Improper output neutralization for logs. https:\/\/cwe.mitre.org\/data\/definitions\/117.html, online; accessed January 2021"},{"key":"10165_CR38","unstructured":"Mitre CWE (2020j) Relative path traversal. https:\/\/cwe.mitre.org\/data\/definitions\/23.html, online; accessed January 2021"},{"key":"10165_CR39","unstructured":"Mitre CWE (2020k) Trust boundary violation. https:\/\/cwe.mitre.org\/data\/definitions\/501.html, online; accessed January 2021"},{"key":"10165_CR40","unstructured":"Mitre CWE (2020l) Url redirection to untrusted site (open redirect). https:\/\/cwe.mitre.org\/data\/definitions\/601.html, online; accessed January 2021"},{"key":"10165_CR41","unstructured":"Mitre CWE (2020m) Xml injection. https:\/\/cwe.mitre.org\/data\/definitions\/91.html, online; accessed January 2021"},{"key":"10165_CR42","doi-asserted-by":"publisher","unstructured":"Naiakshina A, Danilova A, Tiefenau C, Herzog M, Dechand S, Smith M (2017) Why do developers get password storage wrong? A qualitative usability study. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security, CCS 17. https:\/\/doi.org\/10.1145\/3133956.3134082. ACM, New York, pp 311\u2013328","DOI":"10.1145\/3133956.3134082"},{"key":"10165_CR43","unstructured":"Naiakshina A, Danilova A, Tiefenau C, Smith M (2018) Deception task design in developer password studies: exploring a student sample. In: Proceedings of the fourteenth USENIX conference on usable privacy and security, USENIX Association, USA, SOUPS 18, pp 297\u2013313"},{"key":"10165_CR44","doi-asserted-by":"crossref","unstructured":"Naiakshina A, Danilova A, Gerlitz E, von Zezschwitz E, Smith M (2019) If you want, i can store the encrypted password: a password-storage field study with freelance developers. In: Proceedings of the conference on human factors in computing systems, CHI 19. ACM, New York, pp 1\u201312","DOI":"10.1145\/3290605.3300370"},{"key":"10165_CR45","doi-asserted-by":"crossref","unstructured":"Naiakshina A, Danilova A, Gerlitz E, Smith M (2020) On conducting security developer studies with cs students: Examining a password-storage study with cs students, freelancers, and company developers. In: Proceedings of the 2020 CHI conference on human factors in computing systems, CHI 20. ACM, New York, pp 1\u201313","DOI":"10.1145\/3313831.3376791"},{"key":"10165_CR46","doi-asserted-by":"publisher","unstructured":"Nguyen Quang Do L, Bodden E (2020) Explaining static analysis with rule graphs. IEEE Trans Softw Eng 1\u20131. https:\/\/doi.org\/10.1109\/TSE.2020.3004525","DOI":"10.1109\/TSE.2020.3004525"},{"key":"10165_CR47","doi-asserted-by":"publisher","unstructured":"Nguyen Quang Do L, Wright J R, Ali K (2020) Why do software developers use static analysis tools? A user-centered study of developer needs and motivations. In: Proceedings of the sixteenth symposium on usable privacy and security. https:\/\/doi.org\/10.1109\/TSE.2020.3004525","DOI":"10.1109\/TSE.2020.3004525"},{"key":"10165_CR48","unstructured":"OWASP (2020a) Owasp benchmark. https:\/\/owasp.org\/www-project-benchmark\/, online; accessed January 2021"},{"key":"10165_CR49","unstructured":"OWASP OWASP (2020b) Owasp top 10 most critical web application security risks. https:\/\/www.owasp.org\/index.php\/Category:OWASP_Top_Ten_Project, online; accessed January 2021"},{"key":"10165_CR50","doi-asserted-by":"crossref","unstructured":"Pauck F, Bodden E, Wehrheim H (2018) Do android taint analysis tools keep their promises?. In: Proceedings of the 2018 26th ACM joint meeting on european software engineering conference and symposium on the foundations of software engineering, ESEC\/FSE 2018. ACM, New York, pp 331\u2013341","DOI":"10.1145\/3236024.3236029"},{"key":"10165_CR51","doi-asserted-by":"crossref","unstructured":"Piskachev G, Do L N Q, Bodden E (2019) Codebase-adaptive detection of security-relevant methods. In: Proceedings of the 28th ACM SIGSOFT international symposium on software testing and analysis, ISSTA 2019. ACM, New York, pp 181\u2013191","DOI":"10.1145\/3293882.3330556"},{"issue":"12","key":"10165_CR52","first-page":"46","volume":"81","author":"FF Reichheld","year":"2003","unstructured":"Reichheld F F (2003) The one number you need to grow. Harv Bus Rev 81(12):46\u201355","journal-title":"Harv Bus Rev"},{"key":"10165_CR53","doi-asserted-by":"crossref","unstructured":"Sas D, Bessi M, Fontana F A (2018) Automatic detection of sources and sinks in arbitrary java libraries. In: 2018 IEEE 18th International working conference on source code analysis and manipulation (SCAM), pp 103\u2013112","DOI":"10.1109\/SCAM.2018.00019"},{"key":"10165_CR54","doi-asserted-by":"publisher","unstructured":"Schwartz E J, Avgerinos T, Brumley D (2010) All you ever wanted to know about dynamic taint analysis and forward symbolic execution (but might have been afraid to ask). In: 2010 IEEE Symposium on security and privacy. https:\/\/doi.org\/10.1109\/SP.2010.26, pp 317\u2013331","DOI":"10.1109\/SP.2010.26"},{"key":"10165_CR55","unstructured":"SecuCheck RP (2021) Interviews with developers. https:\/\/secucheck.github.io\/, online; accessed January 2021"},{"issue":"9","key":"10165_CR56","doi-asserted-by":"publisher","first-page":"877","DOI":"10.1109\/TSE.2018.2810116","volume":"45","author":"J Smith","year":"2019","unstructured":"Smith J, Johnson B, Murphy-Hill E, Chu B, Lipford H R (2019) How developers diagnose potential security vulnerabilities with a static analysis tool. IEEE Trans Softw Eng 45(9):877\u2013897","journal-title":"IEEE Trans Softw Eng"},{"key":"10165_CR57","unstructured":"Smith J, Nguyen Quang Do L, Murphy-Hill E (2020) Why can\u2019t Johnny fix vulnerabilities: a usability evaluation of static analysis tools for security. In: Proceedings of the sixteenth symposium on usable privacy and security, SOUPS 2020"},{"key":"10165_CR58","doi-asserted-by":"publisher","first-page":"52339","DOI":"10.1109\/ACCESS.2019.2911592","volume":"7","author":"T Song","year":"2019","unstructured":"Song T, Li X, Feng Z, Xu G (2019) Inferring patterns for taint-style vulnerabilities with security patches. IEEE Access 7:52339\u201352349","journal-title":"IEEE Access"},{"issue":"POPL","key":"10165_CR59","first-page":"48:1","volume":"3","author":"J Sp\u00e4th","year":"2019","unstructured":"Sp\u00e4th J, Ali K, Bodden E (2019) Context-, flow-, and field-sensitive data-flow analysis using synchronized pushdown systems. Proceedings of the ACM SIGPLAN symposium on principles of programming languages 3(POPL):48:1\u201348:29","journal-title":"Proceedings of the ACM SIGPLAN symposium on principles of programming languages"},{"issue":"10","key":"10165_CR60","doi-asserted-by":"publisher","first-page":"1053","DOI":"10.1145\/2076021.2048145","volume":"46","author":"M Sridharan","year":"2011","unstructured":"Sridharan M, Artzi S, Pistoia M, Guarnieri S, Tripp O, Berg R (2011) F4f: taint analysis of framework-based web applications. SIGPLAN Not 46(10):1053\u20131068","journal-title":"SIGPLAN Not"},{"key":"10165_CR61","volume-title":"Model-driven software development: technology, engineering, management","author":"T Stahl","year":"2006","unstructured":"Stahl T, Voelter M, Czarnecki K (2006) Model-driven software development: technology, engineering, management. Wiley, Hoboken"},{"key":"10165_CR62","doi-asserted-by":"crossref","unstructured":"Szab\u00f3 T, Erdweg S, Voelter M (2016) Inca: a dsl for the definition of incremental program analyses. In: Proceedings of the 31st IEEE\/ACM international conference on automated software engineering, ASE 2016. ACM, New York, pp 320\u2013331","DOI":"10.1145\/2970276.2970298"},{"key":"10165_CR63","doi-asserted-by":"crossref","unstructured":"Thom\u00e9 J, Shar L K, Bianculli D, Briand L C (2017) Joanaudit: a tool for auditing common injection vulnerabilities. In: Proceedings of the 2017 11th joint meeting on foundations of software engineering, ESEC\/FSE 2017. ACM, New York, pp 1004\u20131008","DOI":"10.1145\/3106237.3122822"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-022-10165-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-022-10165-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-022-10165-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,26]],"date-time":"2022-07-26T05:06:55Z","timestamp":1658812015000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-022-10165-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,5,30]]},"references-count":63,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2022,9]]}},"alternative-id":["10165"],"URL":"https:\/\/doi.org\/10.1007\/s10664-022-10165-y","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"type":"print","value":"1382-3256"},{"type":"electronic","value":"1573-7616"}],"subject":[],"published":{"date-parts":[[2022,5,30]]},"assertion":[{"value":"5 April 2022","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 May 2022","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The user study design has been approved for ethical correctness by one of the companies participated in the study as well as by the corresponding head of department at Fraunhofer IEM.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics Approval"}},{"value":"Not applicable","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"<!--Emphasis Type='Bold' removed-->Conflicts of Interest\/Competing Interests"}}],"article-number":"104"}}