{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,6]],"date-time":"2026-06-06T00:36:59Z","timestamp":1780706219716,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":69,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,5,30]],"date-time":"2022-05-30T00:00:00Z","timestamp":1653868800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"DARPA","award":["FA875019C0003"],"award-info":[{"award-number":["FA875019C0003"]}]},{"name":"DARPA","award":["N6600120C4020"],"award-info":[{"award-number":["N6600120C4020"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,5,30]]},"DOI":"10.1145\/3488932.3497764","type":"proceedings-article","created":{"date-parts":[[2022,5,24]],"date-time":"2022-05-24T04:23:26Z","timestamp":1653366206000},"page":"602-615","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":17,"title":["The Convergence of Source Code and Binary Vulnerability Discovery -- A Case Study"],"prefix":"10.1145","author":[{"given":"Alessandro","family":"Mantovani","sequence":"first","affiliation":[{"name":"EURECOM, Biot, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Luca","family":"Compagna","sequence":"additional","affiliation":[{"name":"SAP Security Research, Sophia Antipolis, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yan","family":"Shoshitaishvili","sequence":"additional","affiliation":[{"name":"Arizona State University, Phoenix, AZ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Davide","family":"Balzarotti","sequence":"additional","affiliation":[{"name":"EURECOM, Biot, France"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,5,30]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"Accessed December 4 2021. Avast Retargetable Decompiler IDA Plugin. https: \/\/blog.fpmurphy.com\/2017\/12\/avast-retargetable-decompiler-ida-plugin.html.  Accessed December 4 2021. Avast Retargetable Decompiler IDA Plugin. https: \/\/blog.fpmurphy.com\/2017\/12\/avast-retargetable-decompiler-ida-plugin.html."},{"key":"e_1_3_2_2_2_1","unstructured":"Accessed December 4 2021. Awesome Static Analysis. https:\/\/github.com\/ analysis-tools-dev\/static-analysis.  Accessed December 4 2021. Awesome Static Analysis. https:\/\/github.com\/ analysis-tools-dev\/static-analysis."},{"key":"e_1_3_2_2_3_1","unstructured":"Accessed December 4 2021. C and C++ Source Code Analysis Tools. https: \/\/www.codeanalysistools.com\/?cplusplus.  Accessed December 4 2021. C and C++ Source Code Analysis Tools. https: \/\/www.codeanalysistools.com\/?cplusplus."},{"key":"e_1_3_2_2_4_1","unstructured":"Accessed December 4 2021. Code-QL. https:\/\/securitylab.github.com\/tools\/ codeql.  Accessed December 4 2021. Code-QL. https:\/\/securitylab.github.com\/tools\/ codeql."},{"key":"e_1_3_2_2_5_1","unstructured":"Accessed December 4 2021. Code-ql queries examples. https:\/\/help.semmle.com\/ QL\/learn-ql\/cpp\/ql-for-cpp.html.  Accessed December 4 2021. Code-ql queries examples. https:\/\/help.semmle.com\/ QL\/learn-ql\/cpp\/ql-for-cpp.html."},{"key":"e_1_3_2_2_6_1","unstructured":"Accessed December 4 2021. CPPCheck. http:\/\/cppcheck.sourceforge.net\/.  Accessed December 4 2021. CPPCheck. http:\/\/cppcheck.sourceforge.net\/."},{"key":"e_1_3_2_2_7_1","unstructured":"Accessed December 4 2021. CWE Checker. https:\/\/github.com\/fkie-cat\/cwe- checker.  Accessed December 4 2021. CWE Checker. https:\/\/github.com\/fkie-cat\/cwe- checker."},{"key":"e_1_3_2_2_8_1","unstructured":"Accessed December 4 2021. flawfinder. https:\/\/github.com\/david-a-wheeler\/ flawfinder.  Accessed December 4 2021. flawfinder. https:\/\/github.com\/david-a-wheeler\/ flawfinder."},{"key":"e_1_3_2_2_9_1","unstructured":"Accessed December 4 2021. framac. https:\/\/frama-c.com\/.  Accessed December 4 2021. framac. https:\/\/frama-c.com\/."},{"key":"e_1_3_2_2_10_1","unstructured":"Accessed December 4 2021. Ghidra. https:\/\/ghidra-sre.org\/.  Accessed December 4 2021. Ghidra. https:\/\/ghidra-sre.org\/."},{"key":"e_1_3_2_2_11_1","unstructured":"Accessed December 4 2021. Hex-Rays Decompiler. https:\/\/www.hex-rays.com\/ products\/decompiler\/.  Accessed December 4 2021. Hex-Rays Decompiler. https:\/\/www.hex-rays.com\/ products\/decompiler\/."},{"key":"e_1_3_2_2_12_1","unstructured":"Accessed December 4 2021. IKOS. https:\/\/github.com\/NASA-SW-VnV\/ikos.  Accessed December 4 2021. IKOS. https:\/\/github.com\/NASA-SW-VnV\/ikos."},{"key":"e_1_3_2_2_13_1","unstructured":"Accessed December 4 2021. Infer. https:\/\/fbinfer.com\/.  Accessed December 4 2021. Infer. https:\/\/fbinfer.com\/."},{"key":"e_1_3_2_2_14_1","unstructured":"Accessed December 4 2021. Joern. https:\/\/joern.io\/.  Accessed December 4 2021. Joern. https:\/\/joern.io\/."},{"key":"e_1_3_2_2_15_1","unstructured":"Accessed December 4 2021. Joern queries examples. https:\/\/github.com\/ ShiftLeftSecurity\/joern\/tree\/master\/joern-cli\/src\/main\/resources\/scripts\/c.  Accessed December 4 2021. Joern queries examples. https:\/\/github.com\/ ShiftLeftSecurity\/joern\/tree\/master\/joern-cli\/src\/main\/resources\/scripts\/c."},{"key":"e_1_3_2_2_16_1","unstructured":"Accessed December 4 2021. RATS. https:\/\/code.google.com\/archive\/p\/rough- auditing-tool-for-security\/.  Accessed December 4 2021. RATS. https:\/\/code.google.com\/archive\/p\/rough- auditing-tool-for-security\/."},{"key":"e_1_3_2_2_17_1","unstructured":"Accessed December 4 2021. Scan-build. https:\/\/clang-analyzer.llvm.org\/.  Accessed December 4 2021. Scan-build. https:\/\/clang-analyzer.llvm.org\/."},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"crossref","unstructured":"Accessed December 4 2021. Veracode. https:\/\/www.veracode.com\/products\/ binary-static-analysis-sast.  Accessed December 4 2021. Veracode. https:\/\/www.veracode.com\/products\/ binary-static-analysis-sast.","DOI":"10.1016\/S1353-4858(21)00016-7"},{"key":"e_1_3_2_2_19_1","unstructured":"Accessed December 4 2021. What are the best sast tools? https:\/\/ cybersecuritykings.com\/2020\/02\/16\/11-tips-on-sast-tool-selection\/.  Accessed December 4 2021. What are the best sast tools? https:\/\/ cybersecuritykings.com\/2020\/02\/16\/11-tips-on-sast-tool-selection\/."},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"crossref","unstructured":"H.H. AlBreiki and Q.H. Mahmoud. 2014. Evaluation of static analysis tools for software security. In IIT.  H.H. AlBreiki and Q.H. Mahmoud. 2014. Evaluation of static analysis tools for software security. In IIT.","DOI":"10.1109\/INNOVATIONS.2014.6987569"},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"crossref","unstructured":"A. Arusoaie S. C. V. Craciun D. Gavrilut and D. Lucanu. 2017. A comparison of open-source static analysis tools for vulnerability detection in c\/c code. In IEEE SYNASC.  A. Arusoaie S. C. V. Craciun D. Gavrilut and D. Lucanu. 2017. A comparison of open-source static analysis tools for vulnerability detection in c\/c code. In IEEE SYNASC.","DOI":"10.1109\/SYNASC.2017.00035"},{"key":"e_1_3_2_2_22_1","volume-title":"International Conference on Computer Aided Verification.","author":"Beyer Dirk","unstructured":"Dirk Beyer and M Erkan Keremoglu . [n.d.]. CPAchecker : A tool for configurable software verification . In International Conference on Computer Aided Verification. Dirk Beyer and M Erkan Keremoglu. [n.d.]. CPAchecker: A tool for configurable software verification. In International Conference on Computer Aided Verification."},{"key":"e_1_3_2_2_23_1","unstructured":"D. Brumley J. Lee E.J. Schwartz and M. Woo. 2013. Native x86 decompilation using semantics-preserving structural analysis and iterative control-flow structuring. In {USENIX}.  D. Brumley J. Lee E.J. Schwartz and M. Woo. 2013. Native x86 decompilation using semantics-preserving structural analysis and iterative control-flow structuring. In {USENIX}."},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"crossref","unstructured":"G. Chatzieleftheriou and P. Katsaros. 2011. Test-driving static analysis tools in search of C code vulnerabilities. In IEEE COMPSAC.  G. Chatzieleftheriou and P. Katsaros. 2011. Test-driving static analysis tools in search of C code vulnerabilities. In IEEE COMPSAC.","DOI":"10.1109\/COMPSACW.2011.26"},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"crossref","unstructured":"B. Chess and G. McGraw. [n.d.]. Static analysis for security. 2004 IEEE S&P ([n. d.]).  B. Chess and G. McGraw. [n.d.]. Static analysis for security. 2004 IEEE S&P ([n. d.]).","DOI":"10.1109\/MSP.2004.111"},{"key":"e_1_3_2_2_26_1","unstructured":"C. Cifuentes and K. J. Gough. [n.d.]. Decompilation of binary programs. Software: Practice and Experience ([n. d.]).  C. Cifuentes and K. J. Gough. [n.d.]. Decompilation of binary programs. Software: Practice and Experience ([n. d.])."},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3173162.3177157"},{"key":"e_1_3_2_2_28_1","volume-title":"Mcsema: Static translation of x86 instructions to llvm. In ReCon.","author":"Dinaburg A.","year":"2014","unstructured":"A. Dinaburg and A. Ruef . 2014 . Mcsema: Static translation of x86 instructions to llvm. In ReCon. A. Dinaburg and A. Ruef. 2014. Mcsema: Static translation of x86 instructions to llvm. In ReCon."},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"crossref","unstructured":"E.N. Dolgova and A.V. Chernov. 2009. Automatic reconstruction of data types in the decompilation problem. Programming and Computer Software (2009).  E.N. Dolgova and A.V. Chernov. 2009. Automatic reconstruction of data types in the decompilation problem. Programming and Computer Software (2009).","DOI":"10.1134\/S0361768809020066"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"crossref","unstructured":"P. Emanuelsson and U. Nilsson. 2008. A comparative study of industrial static analysis tools. Electronic notes in theoretical computer science (2008).  P. Emanuelsson and U. Nilsson. 2008. A comparative study of industrial static analysis tools. Electronic notes in theoretical computer science (2008).","DOI":"10.1016\/j.entcs.2008.06.039"},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"crossref","unstructured":"A. Fatima S. Bibi and R. Hanif. 2018. Comparative study on static code analysis tools for c\/c. In IEEE IBCAST.  A. Fatima S. Bibi and R. Hanif. 2018. Comparative study on static code analysis tools for c\/c. In IEEE IBCAST.","DOI":"10.1109\/IBCAST.2018.8312265"},{"key":"e_1_3_2_2_32_1","unstructured":"J. Feist L. Mounier S. Bardin R. David and M. Potet. 2019. Finding the needle in the heap: combining static analysis and dynamic symbolic execution to trigger use-after-free. In SSPREW.  J. Feist L. Mounier S. Bardin R. David and M. Potet. 2019. Finding the needle in the heap: combining static analysis and dynamic symbolic execution to trigger use-after-free. In SSPREW."},{"key":"e_1_3_2_2_33_1","volume":"201","author":"Fu C.","unstructured":"C. Fu , H. Chen , H. Liu , X. Chen , Y. Tian , F. Koushanfar , and J. Zhao. 201 9. Coda: An end-to-end neural program decompiler. In Advances in Neural Information Processing Systems. 3708--3719. C. Fu, H. Chen, H. Liu, X. Chen, Y. Tian, F. Koushanfar, and J. Zhao. 2019. Coda: An end-to-end neural program decompiler. In Advances in Neural Information Processing Systems. 3708--3719.","journal-title":"J. Zhao."},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"crossref","unstructured":"V. Ganapathy S. Jha D. Chandler D. Melski and David V. 2003. Buffer overrun detection using linear programming and static analysis. In ACM CCS.  V. Ganapathy S. Jha D. Chandler D. Melski and David V. 2003. Buffer overrun detection using linear programming and static analysis. In ACM CCS.","DOI":"10.1145\/948109.948155"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"crossref","unstructured":"A. Gussoni A. Di Federico P. Fezzardi and G. Agosta. 2020. A Comb for Decompiled C Code. In ACM AsiaCCS.  A. Gussoni A. Di Federico P. Fezzardi and G. Agosta. 2020. A Comb for Decompiled C Code. In ACM AsiaCCS.","DOI":"10.1145\/3320269.3384766"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"crossref","unstructured":"B. Hackett M. Das D. Wang and Z. Yang. 2006. Modular checking for buffer overflows in the large. In ICSE.  B. Hackett M. Das D. Wang and Z. Yang. 2006. Modular checking for buffer overflows in the large. In ICSE.","DOI":"10.1145\/1134285.1134319"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"crossref","unstructured":"D. Hovemeyer and W. Pugh. 2007. Finding more null pointer bugs but not too many. In ACM SIGPLAN-SIGSOFT PASTE.  D. Hovemeyer and W. Pugh. 2007. Finding more null pointer bugs but not too many. In ACM SIGPLAN-SIGSOFT PASTE.","DOI":"10.1145\/1251535.1251537"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"crossref","unstructured":"D. Hovemeyer J. Spacco and W. Pugh. 2005. Evaluating and tuning a static analysis to find null pointer bugs. In ACM SIGPLAN-SIGSOFT PASTE.  D. Hovemeyer J. Spacco and W. Pugh. 2005. Evaluating and tuning a static analysis to find null pointer bugs. In ACM SIGPLAN-SIGSOFT PASTE.","DOI":"10.1145\/1108792.1108798"},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"crossref","unstructured":"D. S. Katz J. Ruchti and E. Schulte. 2018. Using recurrent neural networks for decompilation. In IEEE SANER.  D. S. Katz J. Ruchti and E. Schulte. 2018. Using recurrent neural networks for decompilation. In IEEE SANER.","DOI":"10.1109\/SANER.2018.8330222"},{"key":"e_1_3_2_2_40_1","unstructured":"O. Katz Y. Olshaker Y. Goldberg and E. Yahav. 2019. Towards neural decompilation. arXiv preprint arXiv:1905.08325 (2019).  O. Katz Y. Olshaker Y. Goldberg and E. Yahav. 2019. Towards neural decompilation. arXiv preprint arXiv:1905.08325 (2019)."},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"crossref","unstructured":"M. Kim D. Kim E. Kim S. Kim Y. Jang and Y. Kim. 2020. FirmAE: Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis. In ACSAC.  M. Kim D. Kim E. Kim S. Kim Y. Jang and Y. Kim. 2020. FirmAE: Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis. In ACSAC.","DOI":"10.1145\/3427228.3427294"},{"key":"e_1_3_2_2_42_1","doi-asserted-by":"crossref","unstructured":"Y. Kim J. Lee H. Han and K. Choe. 2010. Filtering false alarms of buffer overflow analysis using SMT solvers. Information and Software Technology (2010).  Y. Kim J. Lee H. Han and K. Choe. 2010. Filtering false alarms of buffer overflow analysis using SMT solvers. Information and Software Technology (2010).","DOI":"10.1016\/j.infsof.2009.10.004"},{"key":"e_1_3_2_2_43_1","volume":"200","author":"K.","unstructured":"K. J. Kratkiewicz. 200 5. Evaluating static analysis tools for detecting buffer overflows in c code. Technical Report. HARVARD UNIV CAMBRIDGE MA. K.J. Kratkiewicz. 2005. Evaluating static analysis tools for detecting buffer overflows in c code. Technical Report. HARVARD UNIV CAMBRIDGE MA.","journal-title":"J. Kratkiewicz."},{"key":"e_1_3_2_2_44_1","volume-title":"Retdec: An open-source machine-code decompiler.","author":"J. Kvr","year":"2017","unstructured":"J. Kvr oustek, P. Matula , and P. Zemek . 2017 . Retdec: An open-source machine-code decompiler. J. Kvr oustek, P. Matula, and P. Zemek. 2017. Retdec: An open-source machine-code decompiler."},{"key":"e_1_3_2_2_45_1","volume-title":"Dire: A neural approach to decompiled identifier naming","author":"Lacomis J.","year":"2019","unstructured":"J. Lacomis , P. Yin , E. Schwartz , M. Allamanis , C. Le Goues , G. Neubig , and B. Vasilescu . 2019 . Dire: A neural approach to decompiled identifier naming . In IEEE\/ACM ASE. J. Lacomis, P. Yin, E. Schwartz, M. Allamanis, C. Le Goues, G. Neubig, and B. Vasilescu. 2019. Dire: A neural approach to decompiled identifier naming. In IEEE\/ACM ASE."},{"key":"e_1_3_2_2_46_1","volume-title":"TIE: Principled reverse engineering of types in binary programs.","author":"Lee J.","year":"2011","unstructured":"J. Lee , T. Avgerinos , and D. Brumley . 2011 . TIE: Principled reverse engineering of types in binary programs. (2011). J. Lee, T. Avgerinos, and D. Brumley. 2011. TIE: Principled reverse engineering of types in binary programs. (2011)."},{"key":"e_1_3_2_2_47_1","doi-asserted-by":"crossref","unstructured":"H. Liang S. Liu Y. Zhang and M. Wang. 2017. Improving the precision of static analysis: Symbolic execution based on GCC abstract syntax tree. In SNPD.  H. Liang S. Liu Y. Zhang and M. Wang. 2017. Improving the precision of static analysis: Symbolic execution based on GCC abstract syntax tree. In SNPD.","DOI":"10.1109\/SNPD.2017.8022752"},{"key":"e_1_3_2_2_48_1","doi-asserted-by":"crossref","unstructured":"Z. Liu and S. Wang. 2020. How far we have come: testing decompilation correctness of C decompilers. In SIGSOFT ISSTA.  Z. Liu and S. Wang. 2020. How far we have come: testing decompilation correctness of C decompilers. In SIGSOFT ISSTA.","DOI":"10.1145\/3395363.3397370"},{"key":"e_1_3_2_2_49_1","volume-title":"SoK: Demystifying Binary Lifters Through the Lens of Downstream Applications. In 2022 2022 IEEE Symposium on Security and Privacy (SP) (SP). IEEE Computer Society","author":"Liu Z.","year":"2022","unstructured":"Z. Liu , Y. Yuan , S. Wang , and Y. Bao . 2022 . SoK: Demystifying Binary Lifters Through the Lens of Downstream Applications. In 2022 2022 IEEE Symposium on Security and Privacy (SP) (SP). IEEE Computer Society , Los Alamitos, CA, USA, 453--472. https:\/\/doi.org\/10.1109\/SP46214. 2022 .00027 10.1109\/SP46214.2022.00027 Z. Liu, Y. Yuan, S. Wang, and Y. Bao. 2022. SoK: Demystifying Binary Lifters Through the Lens of Downstream Applications. In 2022 2022 IEEE Symposium on Security and Privacy (SP) (SP). IEEE Computer Society, Los Alamitos, CA, USA, 453--472. https:\/\/doi.org\/10.1109\/SP46214.2022.00027"},{"key":"e_1_3_2_2_50_1","doi-asserted-by":"crossref","unstructured":"S. Ma M. Jiao S. Zhang W. Zhao and D.W. Wang. 2015. Practical null pointer dereference detection via value-dependence analysis. In IEEE ISSREW.  S. Ma M. Jiao S. Zhang W. Zhao and D.W. Wang. 2015. Practical null pointer dereference detection via value-dependence analysis. In IEEE ISSREW.","DOI":"10.1109\/ISSREW.2015.7392049"},{"key":"e_1_3_2_2_51_1","unstructured":"R. Mahmood and Q.H. Mahmoud. 2018. Evaluation of static analysis tools for finding vulnerabilities in Java and C\/C source code. arXiv preprint arXiv:1805.09040 (2018).  R. Mahmood and Q.H. Mahmoud. 2018. Evaluation of static analysis tools for finding vulnerabilities in Java and C\/C source code. arXiv preprint arXiv:1805.09040 (2018)."},{"key":"e_1_3_2_2_52_1","volume-title":"Comparing static security analysis tools using open source software","author":"McLean R. K","unstructured":"R. K McLean . 2012. Comparing static security analysis tools using open source software . In IEEE SERE. R. K McLean. 2012. Comparing static security analysis tools using open source software. In IEEE SERE."},{"key":"e_1_3_2_2_53_1","doi-asserted-by":"crossref","unstructured":"M. Noonan A. Loginov and D. Cok. 2016. Polymorphic type inference for machine code. In ACM SIGPLAN PLDI.  M. Noonan A. Loginov and D. Cok. 2016. Polymorphic type inference for machine code. In ACM SIGPLAN PLDI.","DOI":"10.1145\/2908080.2908119"},{"key":"e_1_3_2_2_54_1","doi-asserted-by":"crossref","unstructured":"J. Pewny B. Garmany R. Gawlik C. Rossow and T. Holz. 2015. Cross-architecture bug search in binary executables. In IEEE S&P.  J. Pewny B. Garmany R. Gawlik C. Rossow and T. Holz. 2015. Cross-architecture bug search in binary executables. In IEEE S&P.","DOI":"10.1109\/SP.2015.49"},{"key":"e_1_3_2_2_55_1","unstructured":"S. Poeplau and A. Francillon. 2020. Symbolic execution with SymCC: Don't interpret compile!. In {USENIX}.  S. Poeplau and A. Francillon. 2020. Symbolic execution with SymCC: Don't interpret compile!. In {USENIX}."},{"key":"e_1_3_2_2_56_1","unstructured":"D. Pozza R. Sisto L. Durante and A. Valenzano. 2006. Comparing lexical analysis tools for buffer overflow detection in network software. In COMSWARE.  D. Pozza R. Sisto L. Durante and A. Valenzano. 2006. Comparing lexical analysis tools for buffer overflow detection in network software. In COMSWARE."},{"key":"e_1_3_2_2_57_1","doi-asserted-by":"crossref","unstructured":"E. Schulte J. Ruchti M. Noonan D. Ciarletta and A. Loginov. 2018. Evolving exact decompilation. In BAR.  E. Schulte J. Ruchti M. Noonan D. Ciarletta and A. Loginov. 2018. Evolving exact decompilation. In BAR.","DOI":"10.14722\/bar.2018.23008"},{"key":"e_1_3_2_2_58_1","doi-asserted-by":"crossref","unstructured":"S. Shiraishi V. Mohan and H. Marimuthu. 2015. Test suites for benchmarks of static analysis tools. In IEEE ISSREW.  S. Shiraishi V. Mohan and H. Marimuthu. 2015. Test suites for benchmarks of static analysis tools. In IEEE ISSREW.","DOI":"10.1109\/ISSREW.2015.7392027"},{"key":"e_1_3_2_2_59_1","doi-asserted-by":"crossref","unstructured":"E. S\u00f6derberg T. Ekman G. Hedin and E. Magnusson. 2013. Extensible intraprocedural flow analysis at the abstract syntax tree level. Science of Computer Programming (2013).  E. S\u00f6derberg T. Ekman G. Hedin and E. Magnusson. 2013. Extensible intraprocedural flow analysis at the abstract syntax tree level. Science of Computer Programming (2013).","DOI":"10.1016\/j.scico.2012.02.002"},{"key":"e_1_3_2_2_60_1","unstructured":"J. Viega J. Bloch Y. Kohno and G. McGraw. [n.d.]. ITS4: A static vulnerability scanner for C and C code. In 2000 ACSAC.  J. Viega J. Bloch Y. Kohno and G. McGraw. [n.d.]. ITS4: A static vulnerability scanner for C and C code. In 2000 ACSAC."},{"key":"e_1_3_2_2_61_1","unstructured":"D. A. Wagner J. S Foster E. A. Brewer and A. Aiken. 2000. A first step towards automated detection of buffer overrun vulnerabilities.. In NDSS.  D. A. Wagner J. S Foster E. A. Brewer and A. Aiken. 2000. A first step towards automated detection of buffer overrun vulnerabilities.. In NDSS."},{"key":"e_1_3_2_2_62_1","volume-title":"arMajumd","author":"Xu R.","year":"2008","unstructured":"R. Xu , P. Godefroid , and R. arMajumd . 2008 . Testing for buffer overflows with length abstraction. In ISSTA. R. Xu, P. Godefroid, and R. arMajumd. 2008. Testing for buffer overflows with length abstraction. In ISSTA."},{"key":"e_1_3_2_2_63_1","doi-asserted-by":"crossref","unstructured":"K. Yakdan S. Dechand E. Gerhards-Padilla and M. Smith. 2016. Helping johnny to analyze malware: A usability-optimized decompiler and malware analysis user study. In IEEE S&P.  K. Yakdan S. Dechand E. Gerhards-Padilla and M. Smith. 2016. Helping johnny to analyze malware: A usability-optimized decompiler and malware analysis user study. In IEEE S&P.","DOI":"10.1109\/SP.2016.18"},{"key":"e_1_3_2_2_64_1","doi-asserted-by":"crossref","unstructured":"K. Yakdan S. Eschweiler E. Gerhards-Padilla and M. Smith. 2015. No More Gotos: Decompilation Using Pattern-Independent Control-Flow Structuring and Semantic-Preserving Transformations.. In NDSS.  K. Yakdan S. Eschweiler E. Gerhards-Padilla and M. Smith. 2015. No More Gotos: Decompilation Using Pattern-Independent Control-Flow Structuring and Semantic-Preserving Transformations.. In NDSS.","DOI":"10.14722\/ndss.2015.23185"},{"key":"e_1_3_2_2_65_1","doi-asserted-by":"crossref","unstructured":"F. Yamaguchi N. Golde D. Arp and K. Rieck. [n.d.]. Modeling and discovering vulnerabilities with code property graphs. In 2014 IEEE S&P.  F. Yamaguchi N. Golde D. Arp and K. Rieck. [n.d.]. Modeling and discovering vulnerabilities with code property graphs. In 2014 IEEE S&P.","DOI":"10.1109\/SP.2014.44"},{"key":"e_1_3_2_2_66_1","doi-asserted-by":"crossref","unstructured":"F. Yamaguchi M. Lottmann and K. Rieck. 2012. Generalized vulnerability extrapolation using abstract syntax trees. In ACSAC.  F. Yamaguchi M. Lottmann and K. Rieck. 2012. Generalized vulnerability extrapolation using abstract syntax trees. In ACSAC.","DOI":"10.1145\/2420950.2421003"},{"key":"e_1_3_2_2_67_1","volume":"201","author":"Yan H.","unstructured":"H. Yan , Y. Sui , S. Chen , and J. Xue. 201 7. Machine-learning-guided typestate analysis for static use-after-free detection. In ACSAC. H. Yan, Y. Sui, S. Chen, and J. Xue. 2017. Machine-learning-guided typestate analysis for static use-after-free detection. In ACSAC.","journal-title":"J. Xue."},{"key":"e_1_3_2_2_68_1","volume":"201","author":"Yan H.","unstructured":"H. Yan , Y. Sui , S. Chen , and J. Xue. 201 8. Spatio-temporal context reduction: A pointer-analysis-based static approach for detecting use-after-free vulnerabilities. In ICSE. H. Yan, Y. Sui, S. Chen, and J. Xue. 2018. Spatio-temporal context reduction: A pointer-analysis-based static approach for detecting use-after-free vulnerabilities. In ICSE.","journal-title":"J. Xue."},{"key":"e_1_3_2_2_69_1","volume-title":"Poster: Uafchecker: Scalable static detection of use-after-free vulnerabilities. In ACM CCS.","author":"Ye J.","year":"2014","unstructured":"J. Ye , C. Zhang , and X. Han . 2014 . Poster: Uafchecker: Scalable static detection of use-after-free vulnerabilities. In ACM CCS. J. Ye, C. Zhang, and X. Han. 2014. Poster: Uafchecker: Scalable static detection of use-after-free vulnerabilities. In ACM CCS."}],"event":{"name":"ASIA CCS '22: ACM Asia Conference on Computer and Communications Security","location":"Nagasaki Japan","acronym":"ASIA CCS '22","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3488932.3497764","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/abs\/10.1145\/3488932.3497764","content-type":"text\/html","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3488932.3497764","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3488932.3497764","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:48:29Z","timestamp":1750193309000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3488932.3497764"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,5,30]]},"references-count":69,"alternative-id":["10.1145\/3488932.3497764","10.1145\/3488932"],"URL":"https:\/\/doi.org\/10.1145\/3488932.3497764","relation":{},"subject":[],"published":{"date-parts":[[2022,5,30]]},"assertion":[{"value":"2022-05-30","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}