{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T15:45:33Z","timestamp":1783439133539,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":77,"publisher":"ACM","license":[{"start":{"date-parts":[[2019,11,6]],"date-time":"2019-11-06T00:00:00Z","timestamp":1572998400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100007297","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["ONR-N00014-17-1-2498"],"award-info":[{"award-number":["ONR-N00014-17-1-2498"]}],"id":[{"id":"10.13039\/100007297","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["SBIR-1647681, SBIR-1758628"],"award-info":[{"award-number":["SBIR-1647681, SBIR-1758628"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2019,11,6]]},"DOI":"10.1145\/3319535.3345659","type":"proceedings-article","created":{"date-parts":[[2019,11,7]],"date-time":"2019-11-07T13:08:32Z","timestamp":1573132112000},"page":"2455-2472","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":117,"title":["CryptoGuard"],"prefix":"10.1145","author":[{"given":"Sazzadur","family":"Rahaman","sequence":"first","affiliation":[{"name":"Virginia Tech, Blacksburg, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ya","family":"Xiao","sequence":"additional","affiliation":[{"name":"Virginia Tech, Blacksburg, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sharmin","family":"Afrose","sequence":"additional","affiliation":[{"name":"Virginia Tech, Blacksburg, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fahad","family":"Shaon","sequence":"additional","affiliation":[{"name":"University of Texas at Dallas, Dallas, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ke","family":"Tian","sequence":"additional","affiliation":[{"name":"Virginia Tech, Blacksburg, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Miles","family":"Frantz","sequence":"additional","affiliation":[{"name":"Virginia Tech, Blacksburg, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Murat","family":"Kantarcioglu","sequence":"additional","affiliation":[{"name":"University of Texas at Dallas, Dallas, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Danfeng (Daphne)","family":"Yao","sequence":"additional","affiliation":[{"name":"Virginia Tech, Blacksburg, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2019,11,6]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"CogniCrypt_SAST for Android.  CogniCrypt_SAST for Android."},{"key":"e_1_3_2_2_2_1","unstructured":"Coverity Static Application Security Testing (SAST).  Coverity Static Application Security Testing (SAST)."},{"key":"e_1_3_2_2_3_1","unstructured":"Spotbugs: Find Bugs in Java Programs.  Spotbugs: Find Bugs in Java Programs."},{"key":"e_1_3_2_2_4_1","volume-title":"https:\/\/www.keylength.com\/en\/4\/,2016. [Online","year":"2018","unstructured":"Cryptographic Key Length Recommendation. https:\/\/www.keylength.com\/en\/4\/,2016. [Online ; accessed 29- Jan- 2018 ]. Cryptographic Key Length Recommendation. https:\/\/www.keylength.com\/en\/4\/,2016. [Online; accessed 29-Jan-2018]."},{"key":"e_1_3_2_2_5_1","volume-title":"How to fix incorrect implementation of Hostname Verifier? https:\/\/stackoverf low.com\/questions\/41312795\/google-play-warning-how-to-fix-incorrect-implementation-of-hostnameverifier","year":"2016","unstructured":"Google Play Warning : How to fix incorrect implementation of Hostname Verifier? https:\/\/stackoverf low.com\/questions\/41312795\/google-play-warning-how-to-fix-incorrect-implementation-of-hostnameverifier , 2016 . [Online; accessed29-Jan-2018]. Google Play Warning: How to fix incorrect implementation of Hostname Verifier? https:\/\/stackoverf low.com\/questions\/41312795\/google-play-warning-how-to-fix-incorrect-implementation-of-hostnameverifier, 2016. [Online; accessed29-Jan-2018]."},{"key":"e_1_3_2_2_6_1","unstructured":"Change the default Crypt Algo to use stronger cryptographic algo. \"https:\/\/issues.apache.org\/jira\/browse\/RANGER-1644\" 2017. [Online; accessed Jan 26 2018].  Change the default Crypt Algo to use stronger cryptographic algo. \"https:\/\/issues.apache.org\/jira\/browse\/RANGER-1644\" 2017. [Online; accessed Jan 26 2018]."},{"key":"e_1_3_2_2_7_1","volume-title":"https:\/\/docs.oracle.com\/javase\/8\/docs\/api\/java\/util\/Random.html,2017. [Online","year":"2018","unstructured":"Class Random. https:\/\/docs.oracle.com\/javase\/8\/docs\/api\/java\/util\/Random.html,2017. [Online ; accessed 29- Jan- 2018 ]. Class Random. https:\/\/docs.oracle.com\/javase\/8\/docs\/api\/java\/util\/Random.html,2017. [Online; accessed 29-Jan-2018]."},{"key":"e_1_3_2_2_8_1","volume-title":"https:\/\/docs.oracle.com\/javase\/8\/docs\/api\/java\/security\/SecureRandom.html","year":"2017","unstructured":"Class Secure Random. https:\/\/docs.oracle.com\/javase\/8\/docs\/api\/java\/security\/SecureRandom.html , 2017 . [Online; accessed 29-Jan-2018]. Class Secure Random. https:\/\/docs.oracle.com\/javase\/8\/docs\/api\/java\/security\/SecureRandom.html, 2017. [Online; accessed 29-Jan-2018]."},{"key":"e_1_3_2_2_9_1","volume-title":"http:\/\/valerieaurora.org\/hash.html,2017. [Online","year":"2018","unstructured":"Lifetimes of cryptographic hash functions. http:\/\/valerieaurora.org\/hash.html,2017. [Online ; accessed 29- Jan- 2018 ]. Lifetimes of cryptographic hash functions. http:\/\/valerieaurora.org\/hash.html,2017. [Online; accessed 29-Jan-2018]."},{"key":"e_1_3_2_2_10_1","volume-title":"http:\/\/project-rainbowcrack.com\/table.htm","year":"2017","unstructured":"List of Rainbow Tables. http:\/\/project-rainbowcrack.com\/table.htm , 2017 .[Online; accessed 29-Jan-2018]. List of Rainbow Tables. http:\/\/project-rainbowcrack.com\/table.htm, 2017.[Online; accessed 29-Jan-2018]."},{"key":"e_1_3_2_2_11_1","volume-title":"https:\/\/issues.apache.org\/jira\/browse\/RANGER-1645,2017. [Online","year":"2018","unstructured":"Update Doc\/Wiki to provide details on using custom encryption key and salt for encryption of credentials. https:\/\/issues.apache.org\/jira\/browse\/RANGER-1645,2017. [Online ; accessed Jan 26, 2018 ]. Update Doc\/Wiki to provide details on using custom encryption key and salt for encryption of credentials. https:\/\/issues.apache.org\/jira\/browse\/RANGER-1645,2017. [Online; accessed Jan 26, 2018]."},{"key":"e_1_3_2_2_12_1","unstructured":"Google rejected app because of Hostname Verifier issue. \"https:\/\/stackoverf low.com\/questions\/48420530\/google-rejected-app-because-of-hostnameverifier-issue\" 2018. [Online; accessed Jan 26 2018].  Google rejected app because of Hostname Verifier issue. \"https:\/\/stackoverf low.com\/questions\/48420530\/google-rejected-app-because-of-hostnameverifier-issue\" 2018. [Online; accessed Jan 26 2018]."},{"key":"e_1_3_2_2_13_1","first-page":"154","volume-title":"Comparing the Usability of Cryptographic APIs","author":"Acar Y.","year":"2017","unstructured":"Y. Acar , M. Backes , S. Fahl , S. Garfinkel , D. Kim , M. L. Mazurek , and C. Stransky . Comparing the Usability of Cryptographic APIs . In IEEE S &P'17, pages 154 -- 171 , 2017 . Y. Acar, M. Backes, S. Fahl, S. Garfinkel, D. Kim, M. L. Mazurek, and C. Stransky. Comparing the Usability of Cryptographic APIs. In IEEE S&P'17, pages 154--171, 2017."},{"key":"e_1_3_2_2_14_1","first-page":"289","volume-title":"You Get Where You're Looking for: The Impact of Information Sources on Code Security","author":"Acar Y.","year":"2016","unstructured":"Y. Acar , M. Backes , S. Fahl , D. Kim , M. L. Mazurek , and C. Stransky . You Get Where You're Looking for: The Impact of Information Sources on Code Security . In IEEE S &P'16, pages 289 -- 305 , 2016 . Y. Acar, M. Backes, S. Fahl, D. Kim, M. L. Mazurek, and C. Stransky. You Get Where You're Looking for: The Impact of Information Sources on Code Security. In IEEE S&P'16, pages 289--305, 2016."},{"key":"e_1_3_2_2_15_1","volume-title":"Too: A Survey of Security Advice forSoftware Developers. In IEEE Secure Development Conference SecDev","author":"Acar Y.","year":"2017","unstructured":"Y. Acar Developers Need Support , Too: A Survey of Security Advice forSoftware Developers. In IEEE Secure Development Conference SecDev , 2017 . Y. Acar et al. Developers Need Support, Too: A Survey of Security Advice forSoftware Developers. In IEEE Secure Development Conference SecDev, 2017."},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813707"},{"key":"e_1_3_2_2_17_1","volume-title":"Crypto API-Bench: A Comprehensive Benchmark on Java Cryptographic API Misuses. In IEEE Secure Development Conference (SecDev)","author":"Afrose S.","year":"2019","unstructured":"S. Afrose , S. Rahaman , and D. D. Yao . Crypto API-Bench: A Comprehensive Benchmark on Java Cryptographic API Misuses. In IEEE Secure Development Conference (SecDev) , September 2019 . S. Afrose, S. Rahaman, and D. D. Yao. Crypto API-Bench: A Comprehensive Benchmark on Java Cryptographic API Misuses. In IEEE Secure Development Conference (SecDev), September 2019."},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/2666356.2594299"},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978333"},{"key":"e_1_3_2_2_20_1","first-page":"111","article-title":"The Vulnerability of SSL to Chosen Plaintext Attack","volume":"2004","author":"Bard G. V.","year":"2004","unstructured":"G. V. Bard . The Vulnerability of SSL to Chosen Plaintext Attack . IACR Cryptologye Print Archive , 2004 : 111 , 2004 . G. V. Bard. The Vulnerability of SSL to Chosen Plaintext Attack. IACR Cryptologye Print Archive, 2004:111, 2004.","journal-title":"IACR Cryptologye Print Archive"},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-42045-0_18"},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978423"},{"key":"e_1_3_2_2_23_1","volume-title":"IKE and SSH. In NDSS'16","author":"Bhargavan K.","year":"2016","unstructured":"K. Bhargavan and G. Leurent . Transcript Collision Attacks: Breaking Authentication in TLS , IKE and SSH. In NDSS'16 , 2016 . K. Bhargavan and G. Leurent. Transcript Collision Attacks: Breaking Authentication in TLS, IKE and SSH. In NDSS'16, 2016."},{"key":"e_1_3_2_2_24_1","volume-title":"Broken Fingers: On the Usage of the Fingerprint API in Android. In 25th Annual Network and Distributed System Security Symposium, NDSS 2018","author":"Bianchi A.","year":"2018","unstructured":"A. Bianchi , Y. Fratantonio , A. Machiry , C. Kruegel , G. Vigna , S. P. H. Chung , and W. Lee . Broken Fingers: On the Usage of the Fingerprint API in Android. In 25th Annual Network and Distributed System Security Symposium, NDSS 2018 , SanDiego, California, USA, February 18--21 , 2018 , 2018. A. Bianchi, Y. Fratantonio, A. Machiry, C. Kruegel, G. Vigna, S. P. H. Chung, and W. Lee. Broken Fingers: On the Usage of the Fingerprint API in Android. In 25th Annual Network and Distributed System Security Symposium, NDSS 2018, SanDiego, California, USA, February 18--21, 2018, 2018."},{"key":"e_1_3_2_2_25_1","volume-title":"Twenty Years of Attacks on the RSA Cryptosystem. NOTICES OF THEAMS, 46(2)","author":"Boneh D.","year":"1999","unstructured":"D. Boneh . Twenty Years of Attacks on the RSA Cryptosystem. NOTICES OF THEAMS, 46(2) , 1999 . D. Boneh. Twenty Years of Attacks on the RSA Cryptosystem. NOTICES OF THEAMS, 46(2), 1999."},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053004"},{"key":"e_1_3_2_2_27_1","volume-title":"Cryptanalytic Time-Memory Tradeoff for Password Hashing Schemes. IACR Cryptology ePrint Archive","author":"Chang D.","year":"2017","unstructured":"D. Chang , A. Jati , S. Mishra , and S. K. Sanadhya . Cryptanalytic Time-Memory Tradeoff for Password Hashing Schemes. IACR Cryptology ePrint Archive , 2017 :603, 2017. D. Chang, A. Jati, S. Mishra, and S. K. Sanadhya. Cryptanalytic Time-Memory Tradeoff for Password Hashing Schemes. IACR Cryptology ePrint Archive, 2017:603, 2017."},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978395"},{"key":"e_1_3_2_2_29_1","first-page":"177","volume-title":"USENIX NSDI'17","author":"Chi A.","year":"2017","unstructured":"A. Chi , R. A. Cochran , M. Nesfield , M. K. Reiter , and C. Sturton . A System to Verify Network Behavior of Known Cryptographic Clients . In USENIX NSDI'17 , pages 177 -- 195 , 2017 . A. Chi, R. A. Cochran, M. Nesfield, M. K. Reiter, and C. Sturton. A System to Verify Network Behavior of Known Cryptographic Clients. In USENIX NSDI'17, pages 177--195, 2017."},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.41"},{"key":"e_1_3_2_2_31_1","first-page":"193","volume-title":"USENIX Security'15","author":"de Ruiter J.","year":"2015","unstructured":"J. de Ruiter and E. Poll . Protocol State Fuzzing of TLS Implementations . In USENIX Security'15 , pages 193 -- 206 , 2015 . J. de Ruiter and E. Poll. Protocol State Fuzzing of TLS Implementations. In USENIX Security'15, pages 193--206, 2015."},{"key":"e_1_3_2_2_32_1","volume-title":"https:\/\/continuousassurance.org","author":"SWAMP.","year":"2018","unstructured":"Welcome to the SWAMP. https:\/\/continuousassurance.org , 2018 . Welcome to the SWAMP. https:\/\/continuousassurance.org, 2018."},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516693"},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.11.001"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382205"},{"key":"e_1_3_2_2_36_1","first-page":"294","volume-title":"FPS'15","author":"Gagnon F.","year":"2015","unstructured":"F. Gagnon , M. Ferland , M. Fortier , S. Desloges , J. Ouellet , and C. Boileau . Andro SSL: A Platform to Test Android Applications Connection Security . In FPS'15 , pages 294 -- 302 , 2015 . F. Gagnon, M. Ferland, M. Fortier, S. Desloges, J. Ouellet, and C. Boileau. Andro SSL: A Platform to Test Android Applications Connection Security. In FPS'15, pages 294--302, 2015."},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978420"},{"key":"e_1_3_2_2_38_1","first-page":"655","volume-title":"USENIX Security'16","author":"Garman C.","year":"2016","unstructured":"C. Garman , M. Green , G. Kaptchuk , I. Miers , and M. Rushanan . Dancing on the Lip of the Volcano: Chosen Ciphertext Attacks on Apple iMessage . In USENIX Security'16 , pages 655 -- 672 , 2016 . C. Garman, M. Green, G. Kaptchuk, I. Miers, and M. Rushanan. Dancing on the Lip of the Volcano: Chosen Ciphertext Attacks on Apple iMessage. In USENIX Security'16, pages 655--672, 2016."},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382204"},{"issue":"1","key":"e_1_3_2_2_40_1","first-page":"66","article-title":"Randomness and the Netscape browser","volume":"21","author":"Goldberg I.","year":"1996","unstructured":"I. Goldberg and D. Wagner . Randomness and the Netscape browser . Dr Dobb's Journal-Software Tools for the Professional Programmer , 21 ( 1 ): 66 -- 71 , 1996 . I. Goldberg and D. Wagner. Randomness and the Netscape browser. Dr Dobb's Journal-Software Tools for the Professional Programmer, 21(1):66--71, 1996.","journal-title":"Dr Dobb's Journal-Software Tools for the Professional Programmer"},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.38"},{"key":"e_1_3_2_2_42_1","first-page":"205","volume-title":"USENIX Security'12","author":"Heninger N.","year":"2012","unstructured":"N. Heninger , Z. Durumeric , E. Wustrow , and J. A. Halderman . Mining Your Ps and Qs: Detection of Widespread Weak Keys in Network Devices . In USENIX Security'12 , pages 205 -- 220 , 2012 . N. Heninger, Z. Durumeric, E. Wustrow, and J. A. Halderman. Mining Your Ps and Qs: Detection of Widespread Weak Keys in Network Devices. In USENIX Security'12, pages 205--220, 2012."},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1052883.1052895"},{"key":"e_1_3_2_2_44_1","first-page":"672","volume-title":"ICSE'13","author":"Johnson B.","year":"2013","unstructured":"B. Johnson software developers use static analysis tools to find bugs ? In ICSE'13 , pages 672 -- 681 , 2013 . B. Johnson et al. Why don't software developers use static analysis tools to find bugs? In ICSE'13, pages 672--681, 2013."},{"key":"e_1_3_2_2_45_1","first-page":"138","volume-title":"CRYPTO'89","author":"Krawczyk H.","year":"1989","unstructured":"H. Krawczyk . How to Predict Congruential Generators . In CRYPTO'89 , pages 138 -- 153 , 1989 . H. Krawczyk. How to Predict Congruential Generators. In CRYPTO'89, pages 138--153, 1989."},{"key":"e_1_3_2_2_46_1","first-page":"931","volume-title":"IEEE\/ACM ASE'17","author":"Kr\u00fcger S.","year":"2017","unstructured":"S. Kr\u00fcger : supporting developers in using cryptography . In IEEE\/ACM ASE'17 , pages 931 -- 936 , 2017 . S. Kr\u00fcger et al. CogniCrypt: supporting developers in using cryptography. In IEEE\/ACM ASE'17, pages 931--936, 2017."},{"key":"e_1_3_2_2_47_1","first-page":"1","volume-title":"ECOOP'18","author":"Kr\u00fcger S.","year":"2018","unstructured":"S. Kr\u00fcger , J. Sp\u00e4th , K. Ali , E. Bodden , and M. Mezini . CrySL: An Extensible Approach to Validating the Correct Usage of Cryptographic APIs . In ECOOP'18 , pages 10: 1 -- 10 :27, 2018 . S. Kr\u00fcger, J. Sp\u00e4th, K. Ali, E. Bodden, and M. Mezini. CrySL: An Extensible Approach to Validating the Correct Usage of Cryptographic APIs. In ECOOP'18, pages 10:1--10:27, 2018."},{"key":"e_1_3_2_2_48_1","volume-title":"NDSS'17","author":"Kwon Y.","year":"2017","unstructured":"Y. Kwon , B. Saltaformaggio , I. L. Kim , K. H. Lee , X. Zhang , and D. Xu . A2C: Selfdestructing exploit executions via input perturbation . In NDSS'17 , 2017 . Y. Kwon, B. Saltaformaggio, I. L. Kim, K. H. Lee, X. Zhang, and D. Xu. A2C: Selfdestructing exploit executions via input perturbation. In NDSS'17, 2017."},{"key":"e_1_3_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/2637166.2637237"},{"key":"e_1_3_2_2_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243783"},{"key":"e_1_3_2_2_51_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(00)00140-7"},{"key":"e_1_3_2_2_52_1","first-page":"144","volume-title":"Program Slicing: Methods and Applications. In IEEE International Workshop on Source Code Analysis and Manipulation SCAM'01","author":"Lucia A. D.","year":"2001","unstructured":"A. D. Lucia . Program Slicing: Methods and Applications. In IEEE International Workshop on Source Code Analysis and Manipulation SCAM'01 , pages 144 -- 151 , 2001 . A. D. Lucia. Program Slicing: Methods and Applications. In IEEE International Workshop on Source Code Analysis and Manipulation SCAM'01, pages 144--151, 2001."},{"key":"e_1_3_2_2_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/2897845.2897896"},{"key":"e_1_3_2_2_54_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66399-9_13"},{"key":"e_1_3_2_2_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180201"},{"key":"e_1_3_2_2_56_1","doi-asserted-by":"publisher","DOI":"10.17487\/RFC8018"},{"key":"e_1_3_2_2_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3106284"},{"key":"e_1_3_2_2_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884790"},{"key":"e_1_3_2_2_59_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23092"},{"key":"e_1_3_2_2_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133977"},{"key":"e_1_3_2_2_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/3192366.3192403"},{"key":"e_1_3_2_2_62_1","volume-title":"Large-Scale Discovery of Hidden Sensitive Operations in Android Apps. In NDSS'17","author":"Pan X.","year":"2017","unstructured":"X. Pan , X. Wang , Y. Duan , X. Wang , and H. Yin . Dark Hazard: Learning-based , Large-Scale Discovery of Hidden Sensitive Operations in Android Apps. In NDSS'17 , 2017 . X. Pan, X. Wang, Y. Duan, X. Wang, and H. Yin. Dark Hazard: Learning-based, Large-Scale Discovery of Hidden Sensitive Operations in Android Apps. In NDSS'17, 2017."},{"key":"e_1_3_2_2_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/1858996.1859089"},{"key":"e_1_3_2_2_64_1","first-page":"61","volume-title":"Program Analysis of Cryptographic Implementationsfor Security. In IEEE Secure Development Conference (SecDev), 2017","author":"Rahaman S.","year":"2017","unstructured":"S. Rahaman and D. Yao . Program Analysis of Cryptographic Implementationsfor Security. In IEEE Secure Development Conference (SecDev), 2017 , pages 61 -- 68 , 2017 . S. Rahaman and D. Yao. Program Analysis of Cryptographic Implementationsfor Security. In IEEE Secure Development Conference (SecDev), 2017, pages 61--68, 2017."},{"key":"e_1_3_2_2_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2004.1"},{"key":"e_1_3_2_2_66_1","first-page":"521","volume-title":"HVLearn: Automated Black-Box Analysis of Hostname Verification in SSL\/TLS Implementations","author":"Sivakorn S.","year":"2017","unstructured":"S. Sivakorn , G. Argyros , K. Pei , A. D. Keromytis , and S. Jana . HVLearn: Automated Black-Box Analysis of Hostname Verification in SSL\/TLS Implementations . In IEEE S &P'17, pages 521 -- 538 , 2017 . S. Sivakorn, G. Argyros, K. Pei, A. D. Keromytis, and S. Jana. HVLearn: Automated Black-Box Analysis of Hostname Verification in SSL\/TLS Implementations. In IEEE S&P'17, pages 521--538, 2017."},{"key":"e_1_3_2_2_67_1","first-page":"1492","volume-title":"Systematic Fuzzing and Testing of TLS Libraries. In ACM CCS'16","author":"Somorovsky J.","year":"2016","unstructured":"J. Somorovsky . Systematic Fuzzing and Testing of TLS Libraries. In ACM CCS'16 , pages 1492 -- 1504 , 2016 . J. Somorovsky. Systematic Fuzzing and Testing of TLS Libraries. In ACM CCS'16, pages 1492--1504, 2016."},{"key":"e_1_3_2_2_68_1","volume-title":"Automated Detection of SSL\/TLS Man-in-the-Middle Vulnerabilities in Android Apps. In NDSS'14","author":"Sounthiraraj D.","year":"2014","unstructured":"D. Sounthiraraj , J. Sahs , G. Greenwood , Z. Lin , and L. Khan . SMV-Hunter: Large Scale , Automated Detection of SSL\/TLS Man-in-the-Middle Vulnerabilities in Android Apps. In NDSS'14 , 2014 . D. Sounthiraraj, J. Sahs, G. Greenwood, Z. Lin, and L. Khan. SMV-Hunter: Large Scale, Automated Detection of SSL\/TLS Man-in-the-Middle Vulnerabilities in Android Apps. In NDSS'14, 2014."},{"key":"e_1_3_2_2_69_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63688-7_19"},{"key":"e_1_3_2_2_70_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-72540-4_1"},{"key":"e_1_3_2_2_71_1","unstructured":"Update to Current Use and Deprecation of TDEA 2017. https:\/\/csrc.nist.gov\/news\/2017\/update-to-current-use-and-deprecation-of-tdea.  Update to Current Use and Deprecation of TDEA 2017. https:\/\/csrc.nist.gov\/news\/2017\/update-to-current-use-and-deprecation-of-tdea."},{"key":"e_1_3_2_2_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978406"},{"key":"e_1_3_2_2_73_1","volume-title":"Probabilistic Program Modeling for High-Precision Anomaly Classification. In CSF'15","author":"Xu K.","year":"2015","unstructured":"K. Xu , D. Yao , B. Ryder , and K. Tian . Probabilistic Program Modeling for High-Precision Anomaly Classification. In CSF'15 , July 2015 . K. Xu, D. Yao, B. Ryder, and K. Tian. Probabilistic Program Modeling for High-Precision Anomaly Classification. In CSF'15, July 2015."},{"key":"e_1_3_2_2_74_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASWEC.2008.4483212"},{"key":"e_1_3_2_2_75_1","volume-title":"Morgan & Claypool.","author":"Yao D.","year":"2017","unstructured":"D. Yao , X. Shu , L. Cheng , and S. J. Stolfo . Anomaly Detection as a Service: Challenges, Advances, and Opportunities. In Information Security, Privacy, and Trust Series . Morgan & Claypool. , 2017 . D. Yao, X. Shu, L. Cheng, and S. J. Stolfo. Anomaly Detection as a Service: Challenges, Advances, and Opportunities. In Information Security, Privacy, and Trust Series. Morgan & Claypool., 2017."},{"key":"e_1_3_2_2_76_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180260"},{"key":"e_1_3_2_2_77_1","volume-title":"Why Does Your Data Leak? Uncovering the DataLeakage in Cloud from Mobile Apps","author":"Zuo C.","year":"2019","unstructured":"C. Zuo , Z. Lin , and Y. Zhang . Why Does Your Data Leak? Uncovering the DataLeakage in Cloud from Mobile Apps . In IEEE S &P'16, 2019 . C. Zuo, Z. Lin, and Y. Zhang. Why Does Your Data Leak? Uncovering the DataLeakage in Cloud from Mobile Apps. In IEEE S&P'16, 2019."}],"event":{"name":"CCS '19: 2019 ACM SIGSAC Conference on Computer and Communications Security","location":"London United Kingdom","acronym":"CCS '19","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3319535.3345659","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3319535.3345659","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3319535.3345659","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:24:02Z","timestamp":1750202642000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3319535.3345659"}},"subtitle":["High Precision Detection of Cryptographic Vulnerabilities in Massive-sized Java Projects"],"short-title":[],"issued":{"date-parts":[[2019,11,6]]},"references-count":77,"alternative-id":["10.1145\/3319535.3345659","10.1145\/3319535"],"URL":"https:\/\/doi.org\/10.1145\/3319535.3345659","relation":{},"subject":[],"published":{"date-parts":[[2019,11,6]]},"assertion":[{"value":"2019-11-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}