{"id":"https://openalex.org/W4288079339","doi":"https://doi.org/10.1145/3411495.3421360","title":"The Sound of Silence: Mining Security Vulnerabilities from Secret Integration Channels in Open-Source Projects","display_name":"The Sound of Silence: Mining Security Vulnerabilities from Secret Integration Channels in Open-Source Projects","publication_year":2020,"publication_date":"2020-09-03","ids":{"openalex":"https://openalex.org/W4288079339","doi":"https://doi.org/10.1145/3411495.3421360"},"language":"en","primary_location":{"id":"pmh:oai:arXiv.org:2009.01694","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2009.01694","pdf_url":"https://arxiv.org/pdf/2009.01694","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"type":"preprint","indexed_in":["arxiv"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2009.01694","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5075272510","display_name":"Ralf Ramsauer","orcid":null},"institutions":[{"id":"https://openalex.org/I120163777","display_name":"OTH Regensburg","ror":"https://ror.org/04b9vrm74","country_code":"DE","type":"education","lineage":["https://openalex.org/I120163777"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Ramsauer, Ralf","raw_affiliation_strings":["University of Applied Sciences Regensburg, Regensburg, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Applied Sciences Regensburg, Regensburg, Germany","institution_ids":["https://openalex.org/I120163777"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5033477936","display_name":"Lukas Bulwahn","orcid":null},"institutions":[{"id":"https://openalex.org/I1283382300","display_name":"BMW (Germany)","ror":"https://ror.org/05vs9tj88","country_code":"DE","type":"company","lineage":["https://openalex.org/I1283382300","https://openalex.org/I4210156768"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Bulwahn, Lukas","raw_affiliation_strings":["BMW AG, Munich, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"BMW AG, Munich, Germany","institution_ids":["https://openalex.org/I1283382300"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5014327382","display_name":"Daniel Lohmann","orcid":"https://orcid.org/0000-0001-8224-4161"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Lohmann, Daniel","raw_affiliation_strings":["University of Hanover, Hanover, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Hanover, Hanover, Germany","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5021730239","display_name":"Wolfgang Mauerer","orcid":"https://orcid.org/0000-0002-9765-8313"},"institutions":[{"id":"https://openalex.org/I120163777","display_name":"OTH Regensburg","ror":"https://ror.org/04b9vrm74","country_code":"DE","type":"education","lineage":["https://openalex.org/I120163777"]},{"id":"https://openalex.org/I1325886976","display_name":"Siemens (Germany)","ror":"https://ror.org/059mq0909","country_code":"DE","type":"company","lineage":["https://openalex.org/I1325886976"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Mauerer, Wolfgang","raw_affiliation_strings":["University of Applied Sciences Regensburg &amp; Siemens Corporate Research, Regensburg / Munich, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Applied Sciences Regensburg &amp; Siemens Corporate Research, Regensburg / Munich, Germany","institution_ids":["https://openalex.org/I120163777","https://openalex.org/I1325886976"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":1.6249,"has_fulltext":false,"cited_by_count":17,"citation_normalized_percentile":{"value":0.87732662,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9976999759674072,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9925000071525574,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/silence","display_name":"Silence","score":0.6878173351287842},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.5871175527572632},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5766593217849731},{"id":"https://openalex.org/keywords/sound","display_name":"Sound (geography)","score":0.5226378440856934},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.5187842845916748},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5187256932258606},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.4240753948688507},{"id":"https://openalex.org/keywords/business","display_name":"Business","score":0.34402477741241455},{"id":"https://openalex.org/keywords/acoustics","display_name":"Acoustics","score":0.06723016500473022}],"concepts":[{"id":"https://openalex.org/C2781115785","wikidata":"https://www.wikidata.org/wiki/Q502261","display_name":"Silence","level":2,"score":0.6878173351287842},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.5871175527572632},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5766593217849731},{"id":"https://openalex.org/C203718221","wikidata":"https://www.wikidata.org/wiki/Q491713","display_name":"Sound (geography)","level":2,"score":0.5226378440856934},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.5187842845916748},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5187256932258606},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.4240753948688507},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.34402477741241455},{"id":"https://openalex.org/C24890656","wikidata":"https://www.wikidata.org/wiki/Q82811","display_name":"Acoustics","level":1,"score":0.06723016500473022},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"pmh:oai:arXiv.org:2009.01694","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2009.01694","pdf_url":"https://arxiv.org/pdf/2009.01694","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2009.01694","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2009.01694","pdf_url":"https://arxiv.org/pdf/2009.01694","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.4000000059604645}],"awards":[{"id":"https://openalex.org/G2773297097","display_name":null,"funder_award_id":"783163","funder_id":"https://openalex.org/F4320327207","funder_display_name":"Electronic Components and Systems for European Leadership"},{"id":"https://openalex.org/G5678229347","display_name":null,"funder_award_id":"LO 1719/3-1","funder_id":"https://openalex.org/F4320320879","funder_display_name":"Deutsche Forschungsgemeinschaft"}],"funders":[{"id":"https://openalex.org/F4320320879","display_name":"Deutsche Forschungsgemeinschaft","ror":"https://ror.org/018mejw64"},{"id":"https://openalex.org/F4320327207","display_name":"Electronic Components and Systems for European Leadership","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":33,"referenced_works":["https://openalex.org/W1576624296","https://openalex.org/W1603939896","https://openalex.org/W1647671624","https://openalex.org/W1965772655","https://openalex.org/W1986566755","https://openalex.org/W2007210734","https://openalex.org/W2050019454","https://openalex.org/W2136173752","https://openalex.org/W2140920854","https://openalex.org/W2165532165","https://openalex.org/W2168234580","https://openalex.org/W2184923175","https://openalex.org/W2214818406","https://openalex.org/W2339077968","https://openalex.org/W2515891506","https://openalex.org/W2522750366","https://openalex.org/W2739768234","https://openalex.org/W2752929869","https://openalex.org/W2754638064","https://openalex.org/W2766411424","https://openalex.org/W2883613460","https://openalex.org/W2888798936","https://openalex.org/W2918884300","https://openalex.org/W2954494850","https://openalex.org/W2963311060","https://openalex.org/W2976763854","https://openalex.org/W2981343730","https://openalex.org/W3141872514","https://openalex.org/W3144106047","https://openalex.org/W4232563686","https://openalex.org/W4233869839","https://openalex.org/W4285076060","https://openalex.org/W4288356834"],"related_works":["https://openalex.org/W2140535326","https://openalex.org/W1607271848","https://openalex.org/W4251121070","https://openalex.org/W2734809835","https://openalex.org/W2184961913","https://openalex.org/W1965764303","https://openalex.org/W2750153830","https://openalex.org/W2214987084","https://openalex.org/W1964726586","https://openalex.org/W2328453641"],"abstract_inverted_index":{"Public":[0],"development":[1,50,89,178],"processes":[2,179],"are":[3,15,169,180],"a":[4,20,68,126,151],"key":[5],"characteristic":[6],"of":[7,23,81,118,128,134,154,186],"open":[8,177,196],"source":[9,92],"projects.":[10],"However,":[11,189],"fixes":[12,56,168],"for":[13,57],"vulnerabilities":[14,58],"usually":[16],"discussed":[17],"privately":[18],"among":[19],"small":[21],"group":[22],"trusted":[24],"maintainers,":[25],"and":[26,39,43,101,167,213],"integrated":[27],"without":[28],"prior":[29],"public":[30,88,163],"involvement.":[31],"This":[32],"is":[33],"supposed":[34,181],"to":[35,72,91,125,156,159,182,199],"prevent":[36],"early":[37],"disclosure,":[38],"cope":[40],"with":[41],"embargo":[42],"non-disclosure":[44],"agreement":[45],"(NDA)":[46],"rules.":[47],"While":[48],"regular":[49,98],"activities":[51],"leave":[52],"publicly":[53],"available":[54],"traces,":[55],"that":[59,76,104,141,203],"bypass":[60],"the":[61,82,111,114,132,205],"standard":[62,83],"process":[63,99],"do":[64],"not.":[65],"We":[66,137,208],"present":[67],"data-mining":[69],"based":[70],"approach":[71,149,191],"detect":[73],"code":[74,93],"fragments":[75],"arise":[77],"from":[78,106],"such":[79,201],"infringements":[80],"process.":[84],"By":[85],"systematically":[86],"mapping":[87],"artefacts":[90],"repositories,":[94],"we":[95,121],"can":[96],"exclude":[97],"activities,":[100],"infer":[102],"irregularities":[103],"stem":[105],"non-public":[107],"integration":[108],"channels.":[109],"For":[110,145],"Linux":[112,135],"kernel,":[113],"most":[115],"crucial":[116],"component":[117],"many":[119],"systems,":[120],"apply":[122],"our":[123,148,190],"method":[124],"period":[127],"seven":[129],"months":[130],"before":[131,162],"release":[133],"5.4.":[136],"find":[138],"29":[139],"commits":[140],"address":[142],"12":[143],"vulnerabilities.":[144,188],"these":[146],"vulnerabilities,":[147],"provides":[150],"temporal":[152],"advantage":[153],"2":[155],"179":[157],"days":[158],"design":[160],"exploits":[161],"disclosure":[164,174],"takes":[165],"place,":[166],"rolled":[170],"out.":[171],"Established":[172],"responsible":[173],"approaches":[175],"in":[176],"limit":[183],"premature":[184],"visibility":[185],"security":[187],"shows":[192],"that,":[193],"instead,":[194],"they":[195],"additional":[197],"possibilities":[198],"uncover":[200],"changes":[202],"thwart":[204],"very":[206],"premise.":[207],"conclude":[209],"by":[210],"discussing":[211],"implications":[212],"partial":[214],"countermeasures.":[215]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":3},{"year":2023,"cited_by_count":7},{"year":2022,"cited_by_count":4},{"year":2021,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2022-07-28T00:00:00"}
