English
Related papers

Related papers: To Patch, or not To Patch? That is the Question: A…

200 papers

In this paper, we question the common practice of assigning security impact ratings to OS updates. Specifically, we present evidence that ranking updates by their perceived security importance, in order to defer applying some updates,…

Cryptography and Security · Computer Science 2009-04-28 Jeff Arnold , Tim Abbott , Waseem Daher , Gregory Price , Nelson Elhage , Geoffrey Thomas , Anders Kaseorg

There is an overlooked iceberg of problems in end user computing. Spreadsheets are developed by people who are very skilled in their main job function, be it finance, procurement, or production planning, but often have had no formal…

Human-Computer Interaction · Computer Science 2008-06-03 Pat Cleary , Dr David Ball , Mukul Madahar , Simon Thorne , Christopher Gosling , Karen Fernandez

Although system administrators are frequently urged to protect the machines in their network, the fact remains that the decision to protect is far from universal. To better understand this decision, we formulate a decision-theoretic model…

Cryptography and Security · Computer Science 2012-03-15 C. F. Larry Heimann , Alan Nochenson

Bug fixing is a complex and time-consuming task in software development. Bug localization research tends to focus on the accuracy of automated tools that suggest source code files for developers to look at. However, little is known about…

Software Engineering · Computer Science 2026-05-07 Pablo Diaz Pedreira , Tamara Lopez , Michel Wermelinger

The informativeness of security-related commit messages is crucial for patch triage: when high, it enables the rapid distribution and deployment of security fixes. Prior research (Reis et al., 2023) reported, however, that commit messages…

Software Engineering · Computer Science 2026-04-23 Syful Islam , Stefano Zacchiroli

The latency reduction between the discovery of vulnerabilities, the build-up and dissemination of cyber-attacks has put significant pressure on cybersecurity professionals. For that, security researchers have increasingly resorted to…

Cryptography and Security · Computer Science 2022-10-11 Sébastien Gillard , Dimitri Percia David , Alain Mermoud , Thomas Maillart

Foraging is a widespread behavior, and being part of a group may bring several benefits compared to solitary foraging, such as collective pooling of information and reducing environmental uncertainty. Often theoretical models of collective…

Biological Physics · Physics 2024-12-05 Lisa Blum Moyse , Ahmed El Hady

Hardening computer systems against cyberattacks is crucial for security. However, past incidents illustrated, that many system operators struggle with effective system hardening. Hence, many computer systems and applications remain…

Cryptography and Security · Computer Science 2025-07-18 Niklas Busch , Philip Klostermeyer , Jan H. Klemmer , Yasemin Acar , Sascha Fahl

There are a number of forums where people participate under pseudonyms. One example is peer review, where the identity of reviewers for any paper is confidential. When participating in these forums, people frequently engage in "batching":…

Cryptography and Security · Computer Science 2023-09-13 Alexander Goldberg , Giulia Fanti , Nihar B. Shah

Context: Contemporary code review tools are a popular choice for software quality assurance. Using these tools, reviewers are able to post a linkage between two patches during a review discussion. Large development teams that use a…

Software Engineering · Computer Science 2021-06-07 Dong Wang , Raula Gaikovina Kula , Takashi Ishio , Kenichi Matsumoto

Developers of some safety critical systems construct a safety case. Developers changing a system during development or after release must analyse the change's impact on the safety case. Evidence might be invalidated by changes to the system…

Software Engineering · Computer Science 2014-04-29 Omar Jaradat , Patrick Graydon , Iain Bate

System safety refers to a diverse engineering discipline assessing and improving various aspects of safety in socio-technical systems and their software-intensive sub-systems. While system safety has been a vital area of applied research…

Software Engineering · Computer Science 2018-12-21 Mario Gleirscher , Anne Nyokabi

We developed a simulation game to study the effectiveness of decision-makers in overcoming two complexities in building cybersecurity capabilities: potential delays in capability development; and uncertainties in predicting cyber incidents.…

Cryptography and Security · Computer Science 2018-07-04 M. S. Jalali

In a software project, esp. in open-source, a contribution is a valuable piece of work made to the project: writing code, reporting bugs, translating, improving documentation, creating graphics, etc. We are now at the beginning of an…

Software Engineering · Computer Science 2019-06-20 Martin Monperrus

Open source software (OSS) vulnerabilities threaten the security of software systems that use OSS. Vulnerability databases provide valuable information (e.g., vulnerable version and patch) to mitigate OSS vulnerabilities. There arises a…

Software Engineering · Computer Science 2023-10-03 Congying Xu , Bihuan Chen , Chenhao Lu , Kaifeng Huang , Xin Peng , Yang Liu

Large-scale quantitative analyses have shown that individuals frequently talk to each other about similar things in different online spaces. Why do these overlapping communities exist? We provide an answer grounded in the analysis of 20…

Social and Information Networks · Computer Science 2026-02-17 Nathan TeBlunthuis , Charles Kiene , Isabella Brown , Laura Alia Levi , Nicole McGinnis , Benjamin Mako Hill

Vulnerability management strategy, from both organizational and public policy perspectives, hinges on an understanding of the supply of undiscovered vulnerabilities. If the number of undiscovered vulnerabilities is small enough, then a…

Cryptography and Security · Computer Science 2023-04-20 Jonathan M Spring

Information sharing on social networks is ubiquitous, intuitive, and occasionally accidental. However, people may be unaware of the potential negative consequences of disclosures, such as reputational damages. Yet, people use social…

Human-Computer Interaction · Computer Science 2022-07-07 Yefim Shulman , Agnieszka Kitkowska , Joachim Meyer

The authors' industry experiences suggest that compiler warnings, a lightweight version of program analysis, are valuable early bug detection tools. Significant costs are associated with patches and security bulletins for issues that could…

Software Engineering · Computer Science 2022-01-27 Gunnar Kudrjavets , Aditya Kumar , Nachiappan Nagappan , Ayushi Rastogi

The increasing deployment of Artificial Intelligence (AI) and other autonomous algorithmic systems presents the world with new systemic risks. While focus often lies on the function of individual algorithms, a critical and underestimated…

Computers and Society · Computer Science 2026-02-24 Maurice Chiodo , Dennis Müller