Skip to main content

Showing 1–2 of 2 results for author: Effendi, S D B

Searching in archive cs. Search in all archives.
.
  1. Scalable Language Agnostic Taint Tracking using Explicit Data Dependencies

    Authors: Sedick David Baker Effendi, Xavier Pinho, Andrei Michael Dreyer, Fabian Yamaguchi

    Abstract: Taint analysis using explicit whole-program data-dependence graphs is powerful for vulnerability discovery but faces two major challenges. First, accurately modeling taint propagation through calls to external library procedures requires extensive manual annotations, which becomes impractical for large ecosystems. Second, the sheer size of whole-program graph representations leads to serious scala… ▽ More

    Submitted 6 June, 2025; originally announced June 2025.

    Comments: 9 pages including appendix, SOAP'25

    ACM Class: D.2.4

  2. arXiv:2310.00673  [pdf, other

    cs.LG cs.CR

    Learning Type Inference for Enhanced Dataflow Analysis

    Authors: Lukas Seidel, Sedick David Baker Effendi, Xavier Pinho, Konrad Rieck, Brink van der Merwe, Fabian Yamaguchi

    Abstract: Statically analyzing dynamically-typed code is a challenging endeavor, as even seemingly trivial tasks such as determining the targets of procedure calls are non-trivial without knowing the types of objects at compile time. Addressing this challenge, gradual typing is increasingly added to dynamically-typed languages, a prominent example being TypeScript that introduces static typing to JavaScript… ▽ More

    Submitted 4 October, 2023; v1 submitted 1 October, 2023; originally announced October 2023.

    Comments: - fixed last author's name - fixed header

    Journal ref: 28th European Symposium on Research in Computer Security (ESORICS) 2023