Vulnerable open source dependencies: Counting those that matter I Pashchenko, H Plate, SE Ponta, A Sabetta, F Massacci Proceedings of the 12th ACM/IEEE international symposium on empirical …, 2018 | 127 | 2018 |
A qualitative study of dependency management and its security implications I Pashchenko, DL Vu, F Massacci Proceedings of the 2020 ACM SIGSAC conference on computer and communications …, 2020 | 109 | 2020 |
Typosquatting and combosquatting attacks on the python ecosystem DL Vu, I Pashchenko, F Massacci, H Plate, A Sabetta 2020 ieee european symposium on security and privacy workshops (euros&pw …, 2020 | 72 | 2020 |
Towards using source code repositories to identify software supply chain attacks DL Vu, I Pashchenko, F Massacci, H Plate, A Sabetta Proceedings of the 2020 ACM SIGSAC conference on computer and communications …, 2020 | 65 | 2020 |
Vuln4real: A methodology for counting actually vulnerable dependencies I Pashchenko, H Plate, SE Ponta, A Sabetta, F Massacci IEEE Transactions on Software Engineering 48 (5), 1592-1609, 2020 | 61 | 2020 |
Lastpymile: identifying the discrepancy between sources and packages DL Vu, F Massacci, I Pashchenko, H Plate, A Sabetta Proceedings of the 29th ACM Joint Meeting on European Software Engineering …, 2021 | 58 | 2021 |
A fine-grained data set and analysis of tangling in bug fixing commits S Herbold, A Trautsch, B Ledel, A Aghamohammadi, TA Ghaleb, ... Empirical Software Engineering 27 (6), 125, 2022 | 45 | 2022 |
TaintBench: Automatic real-world malware benchmarking of Android taint analyses L Luo, F Pauck, G Piskachev, M Benz, I Pashchenko, M Mory, E Bodden, ... Empirical Software Engineering 27, 1-41, 2022 | 28 | 2022 |
Delta-bench: Differential benchmark for static analysis security testing tools I Pashchenko, S Dashevskyi, F Massacci 2017 ACM/IEEE International Symposium on Empirical Software Engineering and …, 2017 | 22 | 2017 |
Machine learning for source code vulnerability detection: What works and what isn’t there yet T Marjanov, I Pashchenko, F Massacci IEEE Security & Privacy 20 (5), 60-76, 2022 | 20 | 2022 |
Technical leverage in a software ecosystem: Development opportunities and security risks F Massacci, I Pashchenko 2021 IEEE/ACM 43rd International Conference on Software Engineering (ICSE …, 2021 | 15 | 2021 |
Security maturity self-assessment framework for software development lifecycle R Brasoveanu, Y Karabulut, I Pashchenko Proceedings of the 17th International Conference on Availability …, 2022 | 13 | 2022 |
Large-scale manual validation of bug fixing commits: A fine-grained analysis of tangling S Herbold, A Trautsch, B Ledel, A Aghamohammadi, TA Ghaleb, ... arXiv preprint arXiv:2011.06244, 2020 | 10 | 2020 |
Please hold on: more time= more patches? automated program repair as anytime algorithms DL Vu, I Pashchenko, F Massacci 2021 IEEE/ACM International Workshop on Automated Program Repair (APR), 9-10, 2021 | 5 | 2021 |
Secure software development in the era of fluid multi-party open software and services I Pashchenko, R Scandariato, A Sabetta, F Massacci 2021 IEEE/ACM 43rd International Conference on Software Engineering: New …, 2021 | 5 | 2021 |
Technical leverage: Dependencies are a mixed blessing F Massacci, I Pashchenko IEEE Security & Privacy 19 (3), 58-62, 2021 | 5 | 2021 |
Known Vulnerabilities of Open Source Projects: Where Are the Fixes? A Sabetta, SE Ponta, RC Lozoya, M Bezzi, T Sacchetti, M Greco, ... IEEE Security & Privacy, 2024 | 4 | 2024 |
FOSS version differentiation as a benchmark for static analysis security testing tools I Pashchenko Proceedings of the 2017 11th Joint Meeting on Foundations of Software …, 2017 | 4 | 2017 |
Preliminary findings on FOSS dependencies and security: a qualitative study on developers' attitudes and experience I Pashchenko, DL Vu, F Massacci Proceedings of the ACM/IEEE 42nd International Conference on Software …, 2020 | 3 | 2020 |
Decision Support of Security Assessment of Software Vulnerabilities in Industrial Practice I Pashchenko Università degli studi di Trento, 2019 | 3 | 2019 |