{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,6]],"date-time":"2026-07-06T11:25:08Z","timestamp":1783337108053,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":58,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,8,7]],"date-time":"2020-08-07T00:00:00Z","timestamp":1596758400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,8,10]]},"DOI":"10.1145\/3372782.3406266","type":"proceedings-article","created":{"date-parts":[[2020,8,7]],"date-time":"2020-08-07T13:41:45Z","timestamp":1596807705000},"page":"271-281","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":21,"title":["How Secure are our Computer Systems Courses?"],"prefix":"10.1145","author":[{"given":"Majed","family":"Almansoori","sequence":"first","affiliation":[{"name":"University of Wisconsin-Madison, Madison, WI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jessica","family":"Lam","sequence":"additional","affiliation":[{"name":"University of California, San Diego, San Diego, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Elias","family":"Fang","sequence":"additional","affiliation":[{"name":"University of California, San Diego, San Diego, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kieran","family":"Mulligan","sequence":"additional","affiliation":[{"name":"University of Wisconsin-Madison, Madison, WI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Adalbert Gerald","family":"Soosai Raj","sequence":"additional","affiliation":[{"name":"University of California, San Diego, San Diego, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rahul","family":"Chatterjee","sequence":"additional","affiliation":[{"name":"University of Wisconsin-Madison, Madison, WI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,8,7]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Bitbucket. https:\/\/bitbucket.org\/product\/.  Bitbucket. https:\/\/bitbucket.org\/product\/."},{"key":"e_1_3_2_1_2_1","unstructured":"CS courses at UC San Diego. https:\/\/ucsd.edu\/catalog\/courses\/CSE.html.  CS courses at UC San Diego. https:\/\/ucsd.edu\/catalog\/courses\/CSE.html."},{"key":"e_1_3_2_1_3_1","unstructured":"CS courses at UW-Madison. https:\/\/guide.wisc.edu\/courses\/comp_sci\/.  CS courses at UW-Madison. https:\/\/guide.wisc.edu\/courses\/comp_sci\/."},{"key":"e_1_3_2_1_4_1","unstructured":"CWE-121: Stack-based buffer overflow. https:\/\/cwe.mitre.org\/data\/definitions\/121.html.  CWE-121: Stack-based buffer overflow. https:\/\/cwe.mitre.org\/data\/definitions\/121.html."},{"key":"e_1_3_2_1_5_1","unstructured":"CWE-134: Use of externally-controlled format string. https:\/\/cwe.mitre.org\/data\/definitions\/134.html\/.  CWE-134: Use of externally-controlled format string. https:\/\/cwe.mitre.org\/data\/definitions\/134.html\/."},{"key":"e_1_3_2_1_6_1","unstructured":"CWE-190: Integer overflow or wraparound. https:\/\/cwe.mitre.org\/data\/definitions\/190.html\/.  CWE-190: Integer overflow or wraparound. https:\/\/cwe.mitre.org\/data\/definitions\/190.html\/."},{"key":"e_1_3_2_1_7_1","unstructured":"CWE-78: Improper neutralization of special elements used in an os command('os command injection'). https:\/\/cwe.mitre.org\/data\/definitions\/78.html.  CWE-78: Improper neutralization of special elements used in an os command('os command injection'). https:\/\/cwe.mitre.org\/data\/definitions\/78.html."},{"key":"e_1_3_2_1_8_1","unstructured":"CWE-88: Improper neutralization of argument delimiters in a command ('argument injection'). https:\/\/cwe.mitre.org\/data\/definitions\/88.html.  CWE-88: Improper neutralization of argument delimiters in a command ('argument injection'). https:\/\/cwe.mitre.org\/data\/definitions\/88.html."},{"key":"e_1_3_2_1_9_1","unstructured":"CWE-89: Improper neutralization of special elements used in an SQL command('sql injection'). https:\/\/cwe.mitre.org\/data\/definitions\/89.html.  CWE-89: Improper neutralization of special elements used in an SQL command('sql injection'). https:\/\/cwe.mitre.org\/data\/definitions\/89.html."},{"key":"e_1_3_2_1_10_1","unstructured":"Github. https:\/\/github.com\/about.  Github. https:\/\/github.com\/about."},{"key":"e_1_3_2_1_11_1","unstructured":"Gitlab. https:\/\/about.gitlab.com\/.  Gitlab. https:\/\/about.gitlab.com\/."},{"key":"e_1_3_2_1_12_1","unstructured":"Infer. https:\/\/fbinfer.com.  Infer. https:\/\/fbinfer.com."},{"key":"e_1_3_2_1_13_1","unstructured":"Refine web searches. https:\/\/support.google.com\/websearch\/answer\/2466433?hl=en.  Refine web searches. https:\/\/support.google.com\/websearch\/answer\/2466433?hl=en."},{"key":"e_1_3_2_1_14_1","unstructured":"Searching code. https:\/\/help.github.com\/en\/github\/searching-for-information-on-github\/searching-code.  Searching code. https:\/\/help.github.com\/en\/github\/searching-for-information-on-github\/searching-code."},{"key":"e_1_3_2_1_15_1","volume-title":"https:\/\/www.equifaxsecurity2017.com\/consumer-notice\/","author":"Incident Cybersecurity","year":"2018"},{"key":"e_1_3_2_1_16_1","volume-title":"Heap-based buffer overflow. https:\/\/cwe.mitre.org\/data\/definitions\/122.html","year":"2020"},{"key":"e_1_3_2_1_17_1","volume-title":"http:\/\/www. shmoo.com\/phrack\/Phrack49\/p49-14","author":"Aleph One","year":"1996"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2010.62"},{"key":"e_1_3_2_1_19_1","first-page":"168","volume-title":"Proceedings of the 10th Colloquium for Information Systems Security Education","author":"Bishop Matt","year":"2006"},{"key":"e_1_3_2_1_20_1","volume-title":"O'Hallaron David Richard, and O'Hallaron David Richard. Computer systems: a programmer's perspective","author":"Bryant Randal E","year":"2003"},{"key":"e_1_3_2_1_21_1","volume-title":"Proceedings of the 2014 HUIC Education and STEM Conference","author":"Chung Sam","year":"2014"},{"key":"e_1_3_2_1_22_1","first-page":"63","volume-title":"InUSENIX security symposium","author":"Cowan Crispan","year":"1998"},{"key":"e_1_3_2_1_23_1","volume-title":"Reports: SQL injection attacks and malware led to mostdata breaches. https:\/\/www.zdnet.com\/article\/reports-sql-injection-attacks-and-malware-led-to-most-data-breaches\/","author":"Danchev Dancho","year":"2010"},{"key":"e_1_3_2_1_24_1","unstructured":"Fred Donovan. Healthcare industry takes brunt of ransomware at-tacks. https:\/\/healthitsecurity.com\/news\/healthcare-industry-takes-brunt-of-ransomware-attacks\/.  Fred Donovan. Healthcare industry takes brunt of ransomware at-tacks. https:\/\/healthitsecurity.com\/news\/healthcare-industry-takes-brunt-of-ransomware-attacks\/."},{"key":"e_1_3_2_1_25_1","first-page":"54","volume-title":"IEEE Security and Privacy","author":"Fischer Bishop","year":"2005"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.31"},{"key":"e_1_3_2_1_27_1","volume-title":"a reference manual","author":"Harbison Samuel P","year":"2002"},{"key":"e_1_3_2_1_28_1","volume-title":"Morgan Kaufmann","author":"Harris David","year":"2010"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/2676723.2677268"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSEETW.2006.24"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.735847"},{"key":"e_1_3_2_1_32_1","volume-title":"Cyberciege: an extensible tool for information assurance education. Technical report","author":"Irvine Cynthia E","year":"2005"},{"key":"e_1_3_2_1_33_1","unstructured":"Brian W Kernighan and Dennis M Ritchie.The C programming language. 2006.  Brian W Kernighan and Dennis M Ritchie.The C programming language. 2006."},{"key":"e_1_3_2_1_34_1","volume-title":"A Modern Approach","author":"King K. N.","year":"2008"},{"key":"e_1_3_2_1_35_1","volume-title":"Dnc email leak explained. https:\/\/www.vox.com\/2016\/7\/23\/12261020\/dnc-email-leaks-explained","author":"Lee Timothy B.","year":"2016"},{"key":"e_1_3_2_1_36_1","unstructured":"Rahma Mahmood and Qusay H Mahmoud.Evaluation of static analysis tools for finding vulnerabilities in java and c\/c++ source code.arXiv preprintar Xiv:1805.09040 2018.  Rahma Mahmood and Qusay H Mahmoud.Evaluation of static analysis tools for finding vulnerabilities in java and c\/c++ source code.arXiv preprintar Xiv:1805.09040 2018."},{"key":"e_1_3_2_1_37_1","unstructured":"E Marcussen. Graudit. https:\/\/github.com\/wireghoul\/graudit\/.  E Marcussen. Graudit. https:\/\/github.com\/wireghoul\/graudit\/."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/1940976.1940984"},{"key":"e_1_3_2_1_39_1","unstructured":"Suzanne J. Mathews Tia Newhall and Kevin C. Webb. Dive into systems. https:\/\/diveintosystems.cs.swarthmore.edu\/.  Suzanne J. Mathews Tia Newhall and Kevin C. Webb. Dive into systems. https:\/\/diveintosystems.cs.swarthmore.edu\/."},{"key":"e_1_3_2_1_40_1","volume-title":"List of data breaches. https:\/\/en.wikipedia.org\/wiki\/List_of_data_breaches","author":"Mills Elinor","year":"2020"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2009.139"},{"key":"e_1_3_2_1_42_1","volume-title":"Best computer science schools. https:\/\/www.usnews.com\/best-graduate-schools\/top-science-schools\/computer-science-rankings","author":"News U.S.","year":"2018"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.5555\/1060081.1060104"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1236233"},{"key":"e_1_3_2_1_45_1","volume-title":"https:\/\/www.welivesecurity.com\/2020\/03\/12\/european-power-grid-organization-entsoe-cyberattack\/","author":"Owaida Amer","year":"2020"},{"key":"e_1_3_2_1_46_1","volume-title":"The Hardware Software Interface. Morgan kaufmann","author":"David A Patterson and John L Hennessy.Computer Organization and Design ARM Edition","year":"2016"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/1595496.1562909"},{"key":"e_1_3_2_1_48_1","unstructured":"Kostya Serebryany. Libfuzzer: A library for coverage-guided fuzz testing (withinllvm).  Kostya Serebryany. Libfuzzer: A library for coverage-guided fuzz testing (withinllvm)."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/2766457"},{"key":"e_1_3_2_1_50_1","volume-title":"Report reveals play-by-play of first u.s. grid cyber attack. https:\/\/www.eenews.net\/stories\/1061111289\/","author":"Sobczak Blake","year":"2019"},{"key":"e_1_3_2_1_51_1","volume-title":"Advanced programming in the UNIX environment","author":"Richard Stevens W","year":"2008"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/3328778.3366816"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3159450.3159511"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/1231047.1231053"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3287324.3287429"},{"key":"e_1_3_2_1_56_1","unstructured":"David A. Wheeler. Flaw finder. https:\/\/dwheeler.com\/flawfinder\/.  David A. Wheeler. Flaw finder. https:\/\/dwheeler.com\/flawfinder\/."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/2676723.2677280"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/2445196.2445396"}],"event":{"name":"ICER '20: International Computing Education Research Conference","location":"Virtual Event New Zealand","acronym":"ICER '20","sponsor":["SIGCSE ACM Special Interest Group on Computer Science Education"]},"container-title":["Proceedings of the 2020 ACM Conference on International Computing Education Research"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3372782.3406266","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3372782.3406266","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:44:16Z","timestamp":1750203856000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3372782.3406266"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,8,7]]},"references-count":58,"alternative-id":["10.1145\/3372782.3406266","10.1145\/3372782"],"URL":"https:\/\/doi.org\/10.1145\/3372782.3406266","relation":{},"subject":[],"published":{"date-parts":[[2020,8,7]]},"assertion":[{"value":"2020-08-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}