dc.creatorBraga
dc.creatorAlexandre; Dahab
dc.creatorRicardo
dc.date2016
dc.date2017-11-13T13:50:42Z
dc.date2017-11-13T13:50:42Z
dc.date.accessioned2018-03-29T06:07:12Z
dc.date.available2018-03-29T06:07:12Z
dc.identifier978-1-5090-3713-1
dc.identifier2016 Ieee International Conference On Software Quality, Reliability And Security Companion (qrs-c 2016). Ieee Computer Soc, p. 143 - 150, 2016.
dc.identifierWOS:000386627300019
dc.identifier10.1109/QRS-C.2016.23
dc.identifierhttp://ieeexplore.ieee.org/document/7573736/
dc.identifierhttp://repositorio.unicamp.br/jspui/handle/REPOSIP/329244
dc.identifier.urihttp://repositorioslatinoamericanos.uchile.cl/handle/2250/1366269
dc.descriptionThis work analyzes cryptography misuse by software developers, from their contributions to online forums on cryptography-based security and cryptographic programming. We studied three popular forums: Oracle Java Cryptography, Google Android Developers, and Google Android Security Discussions. We applied a data mining technique, namely Apriori, to elicit association rules among cryptographic bad practices, platform-specific issues, cryptographic programming tasks, and cryptography-related use cases. We found that, with surprisingly high probabilities (90% for Java and 71% for Android), several types of cryptography misuse can be found in the posts, but unfortunately masked by technology-specific issues and programming concerns. We also found that cryptographic bad practices frequently occur in pairs or triples. We related triple associations to use cases and tasks, characterizing worst case scenarios of cryptography misuse. Finally, we observed that hard-to-use architectures confuse developers and contribute to perpetuate recurring errors in cryptographic programming.
dc.description143
dc.description150
dc.descriptionIEEE International Conference on Software Quality, Reliability and Security Companion (QRS-C)
dc.descriptionAUG 01-03, 2016
dc.descriptionVienna, AUSTRIA
dc.description
dc.languageEnglish
dc.publisherIEEE Computer Soc
dc.publisherLos Alamitos
dc.relation2016 IEEE International Conference on Software Quality, Reliability and Security Companion (QRS-C 2016)
dc.rightsfechado
dc.sourceWOS
dc.subjectCryptography Misuse
dc.subjectApriori Algorithm
dc.subjectData Mining
dc.subjectJava Cryptographic Architecture
dc.subjectSecure Coding
dc.titleMining Cryptography Misuse In Online Forums
dc.typeActas de congresos


Este ítem pertenece a la siguiente institución