{"id":"https://openalex.org/W4384009698","doi":"https://doi.org/10.1109/msr59073.2023.00079","title":"Control and Data Flow in Security Smell Detection for Infrastructure as Code: Is It Worth the Effort?","display_name":"Control and Data Flow in Security Smell Detection for Infrastructure as Code: Is It Worth the Effort?","publication_year":2023,"publication_date":"2023-05-01","ids":{"openalex":"https://openalex.org/W4384009698","doi":"https://doi.org/10.1109/msr59073.2023.00079"},"language":"en","primary_location":{"id":"doi:10.1109/msr59073.2023.00079","is_oa":false,"landing_page_url":"https://doi.org/10.1109/msr59073.2023.00079","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE/ACM 20th International Conference on Mining Software Repositories (MSR)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5084032561","display_name":"Ruben Opdebeeck","orcid":"https://orcid.org/0000-0002-0938-4843"},"institutions":[{"id":"https://openalex.org/I13469542","display_name":"Vrije Universiteit Brussel","ror":"https://ror.org/006e5kg04","country_code":"BE","type":"education","lineage":["https://openalex.org/I13469542"]}],"countries":["BE"],"is_corresponding":true,"raw_author_name":"Ruben Opdebeeck","raw_affiliation_strings":["Vrije Universiteit Brussel,Brussels,Belgium","Vrije Universiteit Brussel, Brussels, Belgium"],"affiliations":[{"raw_affiliation_string":"Vrije Universiteit Brussel,Brussels,Belgium","institution_ids":["https://openalex.org/I13469542"]},{"raw_affiliation_string":"Vrije Universiteit Brussel, Brussels, Belgium","institution_ids":["https://openalex.org/I13469542"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5056738223","display_name":"Ahmed Zerouali","orcid":"https://orcid.org/0000-0002-2676-3730"},"institutions":[{"id":"https://openalex.org/I13469542","display_name":"Vrije Universiteit Brussel","ror":"https://ror.org/006e5kg04","country_code":"BE","type":"education","lineage":["https://openalex.org/I13469542"]}],"countries":["BE"],"is_corresponding":false,"raw_author_name":"Ahmed Zerouali","raw_affiliation_strings":["Vrije Universiteit Brussel,Brussels,Belgium","Vrije Universiteit Brussel, Brussels, Belgium"],"affiliations":[{"raw_affiliation_string":"Vrije Universiteit Brussel,Brussels,Belgium","institution_ids":["https://openalex.org/I13469542"]},{"raw_affiliation_string":"Vrije Universiteit Brussel, Brussels, Belgium","institution_ids":["https://openalex.org/I13469542"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5042827940","display_name":"Coen De Roover","orcid":"https://orcid.org/0000-0002-1710-1268"},"institutions":[{"id":"https://openalex.org/I13469542","display_name":"Vrije Universiteit Brussel","ror":"https://ror.org/006e5kg04","country_code":"BE","type":"education","lineage":["https://openalex.org/I13469542"]}],"countries":["BE"],"is_corresponding":false,"raw_author_name":"Coen De Roover","raw_affiliation_strings":["Vrije Universiteit Brussel,Brussels,Belgium","Vrije Universiteit Brussel, Brussels, Belgium"],"affiliations":[{"raw_affiliation_string":"Vrije Universiteit Brussel,Brussels,Belgium","institution_ids":["https://openalex.org/I13469542"]},{"raw_affiliation_string":"Vrije Universiteit Brussel, Brussels, Belgium","institution_ids":["https://openalex.org/I13469542"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5084032561"],"corresponding_institution_ids":["https://openalex.org/I13469542"],"apc_list":null,"apc_paid":null,"fwci":11.6901,"has_fulltext":false,"cited_by_count":25,"citation_normalized_percentile":{"value":0.98509398,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":97,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"534","last_page":"545"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9965999722480774,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8247616291046143},{"id":"https://openalex.org/keywords/scripting-language","display_name":"Scripting language","score":0.6072333455085754},{"id":"https://openalex.org/keywords/control-flow","display_name":"Control flow","score":0.5583403706550598},{"id":"https://openalex.org/keywords/indirection","display_name":"Indirection","score":0.5340005159378052},{"id":"https://openalex.org/keywords/code-smell","display_name":"Code smell","score":0.5038463473320007},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4919445216655731},{"id":"https://openalex.org/keywords/security-testing","display_name":"Security testing","score":0.4667779505252838},{"id":"https://openalex.org/keywords/executable","display_name":"Executable","score":0.44482335448265076},{"id":"https://openalex.org/keywords/oracle","display_name":"Oracle","score":0.43404775857925415},{"id":"https://openalex.org/keywords/software-security-assurance","display_name":"Software security assurance","score":0.41312289237976074},{"id":"https://openalex.org/keywords/data-flow-diagram","display_name":"Data flow diagram","score":0.4108086824417114},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.3166022002696991},{"id":"https://openalex.org/keywords/information-security","display_name":"Information security","score":0.2783142328262329},{"id":"https://openalex.org/keywords/cloud-computing-security","display_name":"Cloud computing security","score":0.2456795871257782},{"id":"https://openalex.org/keywords/software-quality","display_name":"Software quality","score":0.23593518137931824},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.2348935604095459},{"id":"https://openalex.org/keywords/security-information-and-event-management","display_name":"Security information and event management","score":0.2176644206047058},{"id":"https://openalex.org/keywords/database","display_name":"Database","score":0.2137834131717682},{"id":"https://openalex.org/keywords/security-service","display_name":"Security service","score":0.19248002767562866},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.14218375086784363},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.11724302172660828},{"id":"https://openalex.org/keywords/software-development","display_name":"Software development","score":0.1125212013721466}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8247616291046143},{"id":"https://openalex.org/C61423126","wikidata":"https://www.wikidata.org/wiki/Q187432","display_name":"Scripting language","level":2,"score":0.6072333455085754},{"id":"https://openalex.org/C160191386","wikidata":"https://www.wikidata.org/wiki/Q868299","display_name":"Control flow","level":2,"score":0.5583403706550598},{"id":"https://openalex.org/C89377073","wikidata":"https://www.wikidata.org/wiki/Q1171224","display_name":"Indirection","level":2,"score":0.5340005159378052},{"id":"https://openalex.org/C133237599","wikidata":"https://www.wikidata.org/wiki/Q2295111","display_name":"Code smell","level":5,"score":0.5038463473320007},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4919445216655731},{"id":"https://openalex.org/C195518309","wikidata":"https://www.wikidata.org/wiki/Q13424265","display_name":"Security testing","level":5,"score":0.4667779505252838},{"id":"https://openalex.org/C160145156","wikidata":"https://www.wikidata.org/wiki/Q778586","display_name":"Executable","level":2,"score":0.44482335448265076},{"id":"https://openalex.org/C55166926","wikidata":"https://www.wikidata.org/wiki/Q2892946","display_name":"Oracle","level":2,"score":0.43404775857925415},{"id":"https://openalex.org/C62913178","wikidata":"https://www.wikidata.org/wiki/Q7554361","display_name":"Software security assurance","level":4,"score":0.41312289237976074},{"id":"https://openalex.org/C489000","wikidata":"https://www.wikidata.org/wiki/Q747385","display_name":"Data flow diagram","level":2,"score":0.4108086824417114},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.3166022002696991},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.2783142328262329},{"id":"https://openalex.org/C184842701","wikidata":"https://www.wikidata.org/wiki/Q370563","display_name":"Cloud computing security","level":3,"score":0.2456795871257782},{"id":"https://openalex.org/C117447612","wikidata":"https://www.wikidata.org/wiki/Q1412670","display_name":"Software quality","level":4,"score":0.23593518137931824},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.2348935604095459},{"id":"https://openalex.org/C103377522","wikidata":"https://www.wikidata.org/wiki/Q3493999","display_name":"Security information and event management","level":4,"score":0.2176644206047058},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.2137834131717682},{"id":"https://openalex.org/C29983905","wikidata":"https://www.wikidata.org/wiki/Q7445066","display_name":"Security service","level":3,"score":0.19248002767562866},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.14218375086784363},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.11724302172660828},{"id":"https://openalex.org/C529173508","wikidata":"https://www.wikidata.org/wiki/Q638608","display_name":"Software development","level":3,"score":0.1125212013721466}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/msr59073.2023.00079","is_oa":false,"landing_page_url":"https://doi.org/10.1109/msr59073.2023.00079","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE/ACM 20th International Conference on Mining Software Repositories (MSR)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.6399999856948853,"display_name":"Industry, innovation and infrastructure","id":"https://metadata.un.org/sdg/9"}],"awards":[],"funders":[{"id":"https://openalex.org/F4320321730","display_name":"Fonds Wetenschappelijk Onderzoek","ror":"https://ror.org/03qtxy027"},{"id":"https://openalex.org/F4320327336","display_name":"Vlaamse regering","ror":null}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":38,"referenced_works":["https://openalex.org/W2153887189","https://openalex.org/W2263636531","https://openalex.org/W2402800985","https://openalex.org/W2407292968","https://openalex.org/W2560855557","https://openalex.org/W2625619418","https://openalex.org/W2755391279","https://openalex.org/W2796047065","https://openalex.org/W2883411629","https://openalex.org/W2900868607","https://openalex.org/W2907854211","https://openalex.org/W2955656327","https://openalex.org/W2963995913","https://openalex.org/W2964097228","https://openalex.org/W2993710525","https://openalex.org/W3040521121","https://openalex.org/W3041762618","https://openalex.org/W3088191102","https://openalex.org/W3090625769","https://openalex.org/W3096231857","https://openalex.org/W3102233117","https://openalex.org/W3112995305","https://openalex.org/W3123074563","https://openalex.org/W3138063364","https://openalex.org/W3154201789","https://openalex.org/W3157440142","https://openalex.org/W3195172275","https://openalex.org/W4213009331","https://openalex.org/W4229772528","https://openalex.org/W4238083912","https://openalex.org/W4281557843","https://openalex.org/W4283071879","https://openalex.org/W4297254899","https://openalex.org/W4312578982","https://openalex.org/W4313563645","https://openalex.org/W4313563702","https://openalex.org/W6712920666","https://openalex.org/W6794464222"],"related_works":["https://openalex.org/W2120086576","https://openalex.org/W2785657790","https://openalex.org/W4232396753","https://openalex.org/W2252827360","https://openalex.org/W2369652520","https://openalex.org/W2204102791","https://openalex.org/W2349004912","https://openalex.org/W2126513753","https://openalex.org/W2164920192","https://openalex.org/W2164556837"],"abstract_inverted_index":{"Infrastructure":[0,38],"as":[1,39],"Code":[2,40],"is":[3,165],"the":[4,53,59,74,95,154,174,216],"practice":[5],"of":[6,58,67,76,117,133,176,198],"developing":[7],"and":[8,55,63,122,137,148,160,180,204],"maintaining":[9],"computing":[10],"infrastructure":[11],"through":[12,178],"executable":[13],"source":[14],"code.":[15],"Unfortunately,":[16],"IaC":[17,97],"has":[18,28],"also":[19],"brought":[20],"about":[21],"new":[22],"cyber":[23],"attack":[24],"vectors.":[25],"Prior":[26],"work":[27],"therefore":[29],"proposed":[30],"static":[31,220],"analyses":[32],"that":[33,131,195],"detect":[34,108,224],"security":[35,91,110,120,127,184,199,225],"smells":[36,121,185,200],"in":[37,83,167,183,227],"files.":[41],"However,":[42],"they":[43],"have":[44],"so":[45],"far":[46],"remained":[47],"at":[48],"a":[49,89,208],"shallow":[50],"level,":[51],"disregarding":[52],"control":[54,135,179],"data":[56,138,181],"flow":[57,139,182],"scripts":[60],"under":[61],"analysis,":[62],"may":[64],"lack":[65],"awareness":[66,132],"specific":[68],"syntactic":[69],"constructs.":[70],"These":[71,213],"limitations":[72],"inhibit":[73],"quality":[75],"their":[77],"results.":[78],"To":[79,169],"address":[80],"these":[81],"limitations,":[82],"this":[84,170],"paper,":[85],"we":[86,172],"present":[87],"GASEL,":[88],"novel":[90],"smell":[92,128],"detector":[93],"for":[94,218],"Ansible":[96,191],"language.":[98],"It":[99],"uses":[100],"graph":[101],"queries":[102],"on":[103,114],"program":[104],"dependence":[105],"graphs":[106],"to":[107,143,158,211,223],"7":[109],"smells.":[111],"Our":[112],"evaluation":[113],"an":[115,163],"oracle":[116],"243":[118],"real-world":[119],"comparison":[123],"against":[124],"two":[125],"state-of-the-art":[126],"detectors":[129],"shows":[130],"syntax,":[134],"flow,":[136],"enables":[140],"our":[141],"approach":[142,164],"substantially":[144],"improve":[145],"both":[146],"precision":[147],"recall.":[149],"We":[150,193],"further":[151],"question":[152],"whether":[153],"additional":[155],"effort":[156],"required":[157],"develop":[159],"run":[161],"such":[162],"justified":[166],"practice.":[168],"end,":[171],"investigate":[173],"prevalence":[175],"indirection":[177],"across":[186],"more":[187],"than":[188],"15":[189],"000":[190],"scripts.":[192],"find":[194],"over":[196,205],"55%":[197],"contain":[201],"data-flow":[202],"indirection,":[203],"32%":[206],"require":[207],"whole-project":[209],"analysis":[210,221],"detect.":[212],"findings":[214],"motivate":[215],"need":[217],"deeper":[219],"tools":[222],"vulnerabilities":[226],"IaC.":[228]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":10},{"year":2024,"cited_by_count":8},{"year":2023,"cited_by_count":6}],"updated_date":"2026-03-04T09:10:02.777135","created_date":"2025-10-10T00:00:00"}
