{"id":"https://openalex.org/W4405109142","doi":"https://doi.org/10.1145/3707454","title":"Vulnerability Repair via Concolic Execution and Code Mutations","display_name":"Vulnerability Repair via Concolic Execution and Code Mutations","publication_year":2024,"publication_date":"2024-12-06","ids":{"openalex":"https://openalex.org/W4405109142","doi":"https://doi.org/10.1145/3707454"},"language":"en","primary_location":{"id":"doi:10.1145/3707454","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3707454","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3707454","source":{"id":"https://openalex.org/S142627899","display_name":"ACM Transactions on Software Engineering and Methodology","issn_l":"1049-331X","issn":["1049-331X","1557-7392"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Software Engineering and Methodology","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3707454","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5052793365","display_name":"Ridwan Shariffdeen","orcid":"https://orcid.org/0000-0001-5409-4864"},"institutions":[{"id":"https://openalex.org/I165932596","display_name":"National University of Singapore","ror":"https://ror.org/01tgyzw49","country_code":"SG","type":"education","lineage":["https://openalex.org/I165932596"]}],"countries":["SG"],"is_corresponding":true,"raw_author_name":"Ridwan Shariffdeen","raw_affiliation_strings":["Department of Computer Science, National University of Singapore School of Computing, Singapore, Singapore","National University of Singapore, Singapore"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, National University of Singapore School of Computing, Singapore, Singapore","institution_ids":["https://openalex.org/I165932596"]},{"raw_affiliation_string":"National University of Singapore, Singapore","institution_ids":["https://openalex.org/I165932596"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5087160003","display_name":"Christopher S. Timperley","orcid":"https://orcid.org/0000-0002-9785-324X"},"institutions":[{"id":"https://openalex.org/I114772536","display_name":"Software Engineering Institute","ror":"https://ror.org/01xqjjn94","country_code":"US","type":"facility","lineage":["https://openalex.org/I114772536","https://openalex.org/I74973139"]},{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Christopher S. Timperley","raw_affiliation_strings":["Software and Societal Systems Department, Carnegie Mellon University, Pittsburgh, Pennsylvania, United States","Carnegie Mellon University, USA"],"affiliations":[{"raw_affiliation_string":"Software and Societal Systems Department, Carnegie Mellon University, Pittsburgh, Pennsylvania, United States","institution_ids":["https://openalex.org/I114772536","https://openalex.org/I74973139"]},{"raw_affiliation_string":"Carnegie Mellon University, USA","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5071232627","display_name":"Yannic Noller","orcid":"https://orcid.org/0000-0002-9318-8027"},"institutions":[{"id":"https://openalex.org/I904495901","display_name":"Ruhr University Bochum","ror":"https://ror.org/04tsk2644","country_code":"DE","type":"education","lineage":["https://openalex.org/I904495901"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Yannic Noller","raw_affiliation_strings":["Ruhr University Bochum, Bochum, Germany","Ruhr University Bochum, Germany"],"affiliations":[{"raw_affiliation_string":"Ruhr University Bochum, Bochum, Germany","institution_ids":["https://openalex.org/I904495901"]},{"raw_affiliation_string":"Ruhr University Bochum, Germany","institution_ids":["https://openalex.org/I904495901"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5032356672","display_name":"Claire Le Goues","orcid":"https://orcid.org/0000-0002-3931-060X"},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Claire Le Goues","raw_affiliation_strings":["Carnegie Mellon University, Pittsburgh, Pennsylvania, United States","Carnegie Mellon University, USA"],"affiliations":[{"raw_affiliation_string":"Carnegie Mellon University, Pittsburgh, Pennsylvania, United States","institution_ids":["https://openalex.org/I74973139"]},{"raw_affiliation_string":"Carnegie Mellon University, USA","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5060115298","display_name":"Abhik Roychoudhury","orcid":"https://orcid.org/0000-0002-7127-1137"},"institutions":[{"id":"https://openalex.org/I165932596","display_name":"National University of Singapore","ror":"https://ror.org/01tgyzw49","country_code":"SG","type":"education","lineage":["https://openalex.org/I165932596"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Abhik Roychoudhury","raw_affiliation_strings":["National University of Singapore, Singapore, Singapore","National University of Singapore, Singapore"],"affiliations":[{"raw_affiliation_string":"National University of Singapore, Singapore, Singapore","institution_ids":["https://openalex.org/I165932596"]},{"raw_affiliation_string":"National University of Singapore, Singapore","institution_ids":["https://openalex.org/I165932596"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5052793365"],"corresponding_institution_ids":["https://openalex.org/I165932596"],"apc_list":null,"apc_paid":null,"fwci":0.9553,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.80327529,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":98},"biblio":{"volume":"34","issue":"4","first_page":"1","last_page":"27"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12423","display_name":"Software Reliability and Analysis Research","score":0.998199999332428,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.996399998664856,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/fuzz-testing","display_name":"Fuzz testing","score":0.9135964512825012},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8643466830253601},{"id":"https://openalex.org/keywords/concolic-testing","display_name":"Concolic testing","score":0.8404712677001953},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.6960989236831665},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.5900508761405945},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.5754291415214539},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.48500701785087585},{"id":"https://openalex.org/keywords/overhead","display_name":"Overhead (engineering)","score":0.4185212254524231},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.39066335558891296},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3754541873931885},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.3680904507637024},{"id":"https://openalex.org/keywords/symbolic-execution","display_name":"Symbolic execution","score":0.35233932733535767},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.2999444007873535}],"concepts":[{"id":"https://openalex.org/C111065885","wikidata":"https://www.wikidata.org/wiki/Q1189053","display_name":"Fuzz testing","level":3,"score":0.9135964512825012},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8643466830253601},{"id":"https://openalex.org/C11219265","wikidata":"https://www.wikidata.org/wiki/Q5158734","display_name":"Concolic testing","level":4,"score":0.8404712677001953},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.6960989236831665},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.5900508761405945},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.5754291415214539},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.48500701785087585},{"id":"https://openalex.org/C2779960059","wikidata":"https://www.wikidata.org/wiki/Q7113681","display_name":"Overhead (engineering)","level":2,"score":0.4185212254524231},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.39066335558891296},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3754541873931885},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.3680904507637024},{"id":"https://openalex.org/C2779639559","wikidata":"https://www.wikidata.org/wiki/Q7661178","display_name":"Symbolic execution","level":3,"score":0.35233932733535767},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.2999444007873535},{"id":"https://openalex.org/C13280743","wikidata":"https://www.wikidata.org/wiki/Q131089","display_name":"Geodesy","level":1,"score":0.0},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3707454","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3707454","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3707454","source":{"id":"https://openalex.org/S142627899","display_name":"ACM Transactions on Software Engineering and Methodology","issn_l":"1049-331X","issn":["1049-331X","1557-7392"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Software Engineering and Methodology","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1145/3707454","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3707454","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3707454","source":{"id":"https://openalex.org/S142627899","display_name":"ACM Transactions on Software Engineering and Methodology","issn_l":"1049-331X","issn":["1049-331X","1557-7392"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Software Engineering and Methodology","raw_type":"journal-article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.7200000286102295}],"awards":[{"id":"https://openalex.org/G3096245918","display_name":null,"funder_award_id":"FA8750-19-1-0501","funder_id":"https://openalex.org/F4320338294","funder_display_name":"Air Force Research Laboratory"}],"funders":[{"id":"https://openalex.org/F4320338294","display_name":"Air Force Research Laboratory","ror":"https://ror.org/02e2egq70"}],"has_content":{"pdf":true,"grobid_xml":false},"content_urls":{"pdf":"https://content.openalex.org/works/W4405109142.pdf"},"referenced_works_count":46,"referenced_works":["https://openalex.org/W777621473","https://openalex.org/W1480909796","https://openalex.org/W1710734607","https://openalex.org/W1991155991","https://openalex.org/W2002934700","https://openalex.org/W2025613610","https://openalex.org/W2061575154","https://openalex.org/W2086406325","https://openalex.org/W2127577307","https://openalex.org/W2138428785","https://openalex.org/W2145373440","https://openalex.org/W2274071363","https://openalex.org/W2296669295","https://openalex.org/W2343875716","https://openalex.org/W2373227884","https://openalex.org/W2767391605","https://openalex.org/W2784876765","https://openalex.org/W2794889478","https://openalex.org/W2795338679","https://openalex.org/W2898024328","https://openalex.org/W2898887472","https://openalex.org/W2901387825","https://openalex.org/W2954183584","https://openalex.org/W2962715466","https://openalex.org/W2963764936","https://openalex.org/W2974889942","https://openalex.org/W2980012492","https://openalex.org/W2998011150","https://openalex.org/W3049735680","https://openalex.org/W3091097332","https://openalex.org/W3102761457","https://openalex.org/W3120634640","https://openalex.org/W3129269689","https://openalex.org/W3156480510","https://openalex.org/W3162747997","https://openalex.org/W3167325648","https://openalex.org/W3176859472","https://openalex.org/W4236837729","https://openalex.org/W4237256801","https://openalex.org/W4244452926","https://openalex.org/W4250682300","https://openalex.org/W4284674057","https://openalex.org/W4285490485","https://openalex.org/W4308641648","https://openalex.org/W4378942602","https://openalex.org/W4384009665"],"related_works":["https://openalex.org/W2777046235","https://openalex.org/W3172606155","https://openalex.org/W3019261932","https://openalex.org/W2186070848","https://openalex.org/W2785720764","https://openalex.org/W3104446232","https://openalex.org/W2984839971","https://openalex.org/W3161338937","https://openalex.org/W4290048282","https://openalex.org/W3203826058"],"abstract_inverted_index":{"Security":[0],"vulnerabilities":[1,28],"detected":[2,122],"via":[3],"techniques":[4],"like":[5,157],"greybox":[6],"fuzzing":[7],"are":[8],"often":[9,78],"fixed":[10],"with":[11],"a":[12,30,46,120,138,167],"significant":[13],"time":[14],"lag.":[15],"This":[16],"increases":[17],"the":[18,21,72,80,83,88,144,164,182,187],"exposure":[19],"of":[20,27,38,82,86,141,166,170],"software":[22],"to":[23,51],"vulnerabilities.":[24],"Automated":[25],"fixing":[26,87],"where":[29],"tool":[31],"can":[32],"generate":[33,53],"fix":[34,54,68,184],"suggestions":[35,55,69],"is":[36,185],"thus":[37],"value.":[39],"In":[40],"this":[41],"work,":[42],"we":[43,96,176],"present":[44],"such":[45,76],"tool,":[47],"called":[48],"CrashRepair":[49,148,192],",":[50],"automatically":[52],"using":[56],"concolic":[57,94],"execution,":[58,95],"specification":[59],"inference,":[60],"and":[61,104,175],"search":[62,107],"techniques.":[63],"Our":[64,116],"approach":[65],"avoids":[66],"generating":[67],"merely":[70],"at":[71,100,172],"crash":[73],"location":[74],"because":[75],"fixes":[77,189],"disable":[79],"manifestation":[81],"error":[84],"instead":[85],"error.":[89],"Instead,":[90],"based":[91],"on":[92,137,179],"sanitizer-guided":[93],"infer":[97],"desired":[98,183],"constraints":[99],"specific":[101],"program":[102],"locations":[103],"then":[105],"opportunistically":[106],"for":[108],"code":[109],"mutations":[110],"that":[111,178],"help":[112],"respect":[113],"those":[114],"constraints.":[115],"technique":[117],"only":[118],"requires":[119],"single":[121],"vulnerability":[123,154],"or":[124],"exploit":[125],"as":[126],"input;":[127],"it":[128],"does":[129],"not":[130],"require":[131],"any":[132],"user-provided":[133],"properties.":[134],"Evaluation":[135],"results":[136],"wide":[139],"variety":[140],"CVEs":[142],"in":[143,163],"VulnLoc":[145],"benchmark,":[146],"show":[147,177],"achieves":[149],"greater":[150],"efficacy":[151],"than":[152],"state-of-the-art":[153],"repair":[155],"tools":[156],"Senx.":[158],"The":[159],"repairs":[160],"suggested":[161],"come":[162],"form":[165],"ranked":[168],"set":[169],"patches":[171],"different":[173],"locations,":[174],"most":[180],"occasions,":[181],"among":[186],"top-3":[188],"reported":[190],"by":[191],".":[193]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":1}],"updated_date":"2026-04-09T08:11:56.329763","created_date":"2025-10-10T00:00:00"}
