1,721,286 research outputs found

    Explainable Static Analysis

    No full text
    Static code analysis is an important tool that aids in the early detection of programming mistakes, including functional aws, performance bottlenecks and security vulnerabilities. Past research in static analysis has mainly focused on the precise and e cient detection of programming mistakes, allowing new analyses to return more accurate results in a shorter time. However, end-user experience in industry has shown high abandonment rates for static analysis tools. Previous work has shown that current analysis tools are ill-adapted to meet the needs of their users, taking a long time to yield results and causing warnings to be frequently misinterpreted. This can quickly make the overall bene t of static analyses deteriorate. In this work, we argue for the need of developing a line of research on aiding users of static analysis tools, e.g., code developers, to better understand the findings reported by those tools. We outline how we plan to address this problem space by a novel line of research that ultimately seeks to change static analysis tools from being tools for static analysis experts to tools that can be mastered by general code developers. To achieve this goal, we plan to develop novel techniques for formulating, inspecting and debugging static analyses and the rule sets they validate programs against

    Going Beyond Counting First Authors in Author Co-citation Analysis

    Get PDF
    The present study examines one of the fundamental aspects of author co-citation analysis (ACA) - the way co-citation counts are defined. Co-citation counting provides the data on which all subsequent statistical analyses and mappings are based, and we compare ACA results based on two different types of co-citation counting - the traditional type that only counts the first one among a cited work's authors on the one hand and a non-traditional type that takes into account the first 5 authors of a cited work on the other hand. Results indicate that the picture produced through this non-traditional author co-citation counting contains more coherent author groups and is therefore considerably clearer. However, this picture represents fewer specialties in the research field being studied than that produced through the traditional first-author co-citation counting when the same number of top-ranked authors is selected and analyzed. Reasons for these effects are discussed

    Variations on the Author

    Get PDF
    “Variations on the Author” discusses two of Eduardo Coutinho’s recent films (Um Dia na Vida, from 2010, and Últimas Conversas, posthumously released in 2015) and their contribution to the general question of documentary authorship. The director’s filmography is characterized by a consistent yet self-effacing form of authorial self-inscription: Coutinho often features as an interviewer that rather than express opinions propels discourses; an interviewer that is good at listening. This mode of self-inscription characterizes him as an author who is not expressive but who is nonetheless markedly present on the screen. In Um Dia na Vida, however, Coutinho is completely absent form the image, while Últimas Conversas, on the contrary, includes a confessional prologue that moves the director from the margins to the center of his films. This article examines the ways in which these works stand out in the filmography of a director who offers new insights into the notion of cinematic authorship

    Appropriate Similarity Measures for Author Cocitation Analysis

    Get PDF
    We provide a number of new insights into the methodological discussion about author cocitation analysis. We first argue that the use of the Pearson correlation for measuring the similarity between authors’ cocitation profiles is not very satisfactory. We then discuss what kind of similarity measures may be used as an alternative to the Pearson correlation. We consider three similarity measures in particular. One is the well-known cosine. The other two similarity measures have not been used before in the bibliometric literature. Finally, we show by means of an example that our findings have a high practical relevance.information science;Pearson correlation;cosine;similarity measure;author cocitation analysis

    Android-Malware-Erkennung durch maschinelles Lernen

    No full text
    Android ist das beliebteste Betriebssystem für mobile Geräte. Ein großes Problem stellen die zahlreichen Malware- Apps dar, die in den App-Stores angeboten werden. In dieser Arbeit wird untersucht, wie gut man mithilfe von statischer Analyse und maschinellen Lernverfahren Malware-Apps erkennen kann. Dazu wurde das Appicaptor-Framework zur Analyse von mobilen Applikationen, das vom Fraunhofer SIT entwickelt wird, um eine auf maschinellen Lernalgorithmen basierende Malware-Klassifikation erweitert. Die Erkennungsrate und die Laufzeit- Performance des Frameworks wurden in Testläufen mit mehreren zehntausend Apps evaluiert. Dabei wurde eine maximale Malware-Erkennungsrate von über 90% bei einer False-Positive-Rate von weniger als 2,5% erreicht. Außerdem wird gezeigt, dass der Ansatz robust gegen bestimmte Arten von Obfuskierungen ist. Ein wesentliches Ergebnis der Untersuchungen ist, dass eine ausschließlich auf maschinellen Lernverfahren und statischen Features beruhende Malware-Klassifikation noch nicht zuverlässig genug ist, weil die False-Positive-Rate zu hoch ist. Dennoch sind ist der Ansatz für eine Vorselektierung zu analysierender Apps hilfreich. Es werden Vorschläge zu möglichen Erweiterungen des Frameworks genannt, um die Erkennungsrate weiter zu verbessern

    Fluss-insensitive Informationsflussanalyse (für Android)

    No full text
    Information flow analysis is an approach to check whether there is no propagation of information that violates a certain policy in a given program. Flow sensitive analyses, of which implementations for Java already exist, can be very precise in finding malicious flows, but require a lot of resources in terms of computation time and memory consumption. Therefore there is need for a flow-insensitive analysis which can be run faster, yielding results with lesser precision while retaining a high recall. Such an analysis would have several possible applications, e.g. it could be used to analyze a high number of programs to determine which of these contain violations, in order to use flow sensitive analyses on those. This Bachelors thesis provides an implementation of such an analysis based on an already existing pointer analysis. The performance will be compared to an already existing flow sensitive analysis, as well

    Ernst Denert Award for Software Engineering 2022

    No full text
    This open access book provides an overview of the dissertations of the five nominees for the Ernst Denert Award for Software Engineering in 2022. The prize, kindly sponsored by the Gerlind & Ernst Denert Stiftung, is awarded for excellent work within the discipline of Software Engineering, which includes methods, tools and procedures for better and efficient development of high quality software. An essential requirement for the nominated work is its applicability and usability in industrial practice. The book contains five papers that describe the works by Jannik Fischbach (Netlight Consulting GmbH and fortiss GmbH), who won the award, entitled Conditional Statements in Requirements Artifacts: Logical Interpretation, Use Cases for Automated Software Engineering, and Fine-Grained Extraction, Christian Kirchhof's (RWTH Aachen University) From Design to Reality: An Overview of the MontiThings Ecosystem for Model-Driven IoT Applications, Sven Peldszus's (Ruhr University Bochum) research about Security Compliance in Model-driven Development of Software Systems in Presence of Long-Term Evolution and Variants, Florian Rademacher's (RWTH Aachen University) work on Model-Driven Engineering of Microservice Architectures, and Alexander Trautsch's (University of Passau) Usefulness of Automatic Static Analysis Tools: Evidence from Four Case Studies. The chapters describe key findings of the respective works, show their relevance and applicability to practice and industrial software engineering projects, and provide additional information and findings that have only been discovered afterwards, e.g. when applying the results in industry. This way, the book is not only interesting to other researchers, but also to industrial software professionals who would like to learn about the application of state-of-the-art methods in their daily work

    Dispelling the Myths Behind First-author Citation Counts

    Get PDF
    We conducted a full-scale evaluative citation analysis study of scholars in the XML research field to explore just how different from each other author rankings resulting from different citation counting methods actually are, and to demonstrate the capability of emerging data and tools on the Web in supporting more realistic citation counting methods. Our results contest some common arguments for the continued use of first-author citation counts in the evaluation of scholars, such as high correlations between author rankings by first-author citation counts and other citation counting methods, and high costs of using more realistic citation counting methods that are not well-supported by the ISI databases. It is argued that increasingly available digital full text research papers make it possible for citation analysis studies to go beyond what the ISI databases have directly supported and to employ more sophisticated methods
    corecore