application security

Designs, builds, and evaluates security controls, architectures, and processes that protect software applications across their lifecycle, including authentication and authorization, secure coding practices, input validation, session and secret management, dependency and container hardening, and runtime protections. Performs threat modeling, vulnerability analysis, static and dynamic application testing, secure CI/CD pipeline configuration, and implements mitigations for common application-level attacks such as injection, XSS, CSRF, and privilege escalation.

applicationsecurity

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.66
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$185K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This work addresses the vulnerability of build system code to poisoning attacks, which pose a critical threat to software supply chain security. While existing tools primarily focus on application source code, they largely overlook the security of the build process itself. To bridge this gap, we propose a novel paradigm—“development-phase isolation”—that, for the first time, incorporates build scripts into the scope of security analysis. By leveraging information flow tracking and behavioral privilege modeling, our approach enables fine-grained monitoring of build-time code execution. We implement this methodology in a prototype tool, Foreman, which effectively detects anomalous and malicious behaviors within build scripts. In real-world evaluations, Foreman successfully identified the poisoned test files used in the recent XZ Utils supply chain attack, demonstrating both the efficacy and practicality of our approach.

build system securityC codedevelopment phase isolation

This work addresses the challenge of detecting multi-stage attacks that traverse trust boundaries in cloud deployments—threats often missed by conventional security tools due to their inability to model holistic system architecture and runtime behavioral deviations. The authors propose a novel approach that integrates static configuration analysis with runtime network flow observation to automatically construct a platform-agnostic architectural abstraction reflecting the system’s true state, including components, domains, interfaces, policies, and data flows. Building upon this representation, the method enables continuous, architecture-level threat modeling. It is the first to support automated architecture inference and threat detection across bare-metal, Kubernetes, and cloud environments. Evaluated on supply chain systems incorporating machine learning (ML) components, the approach successfully identified all 17 classes of injection threats—including ML-specific threats—substantially outperforming existing tools, which cover only 6–47% of these threats and fail entirely to detect ML-related ones.

cloud securitymulti-stage attacksruntime behavior

To address the challenges of identifying static security vulnerabilities in proprietary and open-source software, unclear vulnerability remediation priorities, and escalating software supply chain risks, this paper proposes an end-to-end, customizable Static Application Security Testing (SAST) workflow. The workflow enables multi-tool orchestration, iterative scanning, and seamless DevSecOps integration, incorporating AI-driven vulnerability prioritization and automated remediation governance as key innovations. Leveraging a generalized process design with environment-adaptive configuration, it significantly improves detection coverage and remediation efficiency. Experimental evaluation in industrial settings demonstrates that the approach reduces source-code-level vulnerabilities by 32.7%, mitigates third-party component–introduced risks by 41.5%, and ensures backward compatibility with legacy systems while supporting scalable deployment across heterogeneous environments.

Creating configurable DevSecOps workflow for prioritized vulnerability remediationDeveloping adaptable process for scanning proprietary and open-source software vulnerabilitiesReducing source code vulnerabilities and supply chain risks in SDLC

This study addresses the practical challenge of integrating Dynamic Application Security Testing (DAST) into agile development—specifically, its resistance to “shifting left” and misalignment with Kanban and CI/CD pipelines. Using action research, complemented by semi-structured interviews and qualitative analysis, we systematically investigate DAST adaptation mechanisms within incremental Kanban workflows and high-velocity CI/CD pipelines. Our key contributions include: (1) a developer-centric, lightweight security gate design; (2) a real-time feedback闭环 strategy; and (3) the first industrial-grade DAST integration framework tailored for agile contexts. Empirical validation identified six critical implementation barriers and yielded reusable mitigation strategies, achieving a 42% average reduction in mean time to remediate vulnerabilities. The framework effectively bridges the trade-off between delivery speed and security assurance, enabling organizations to simultaneously achieve rapid software delivery and built-in security.

Balancing security engineering with Agile development practicesIdentifying and mitigating vulnerabilities in iterative development processesIntegrating DAST into Kanban and CI/CD workflows

Latest Papers

What's happening recently
View more

This work addresses the limitations of existing large language models, which are typically confined to isolated tasks and struggle to integrate into industrial-scale, multi-stage security workflows. To bridge this gap, the authors propose the first role-based multi-agent framework tailored to the entire vulnerability lifecycle, incorporating specialized agents—Planner, Analyzer, Fixer, and Verifier—augmented with CodeQL static analysis for enhanced precision. By introducing a role-oriented multi-agent architecture into end-to-end vulnerability management, this approach effectively aligns the capabilities of large models with real-world security engineering demands. Evaluated on 25 real-world C/C++ vulnerabilities, the system achieves a detection accuracy of 44%—comparable to GPT-5.5—and a repair accuracy of 19%, offering a practical and collaborative paradigm for intelligent security operations.

LLM-based securityrole-based agentic architecturesecure software engineering

Traditional security testing tools deployed in CI/CD pipelines lack adaptability and struggle to effectively integrate program structure with dynamic feedback, resulting in low detection efficiency and high false-positive rates. This work presents a systematic survey of adaptive and AI-enhanced security testing approaches, introducing for the first time the notion of “structural-adaptive disconnection” to highlight the systemic misalignment between program structure representations and adaptive mechanisms. It advocates for incorporating human-in-the-loop signals into a closed-loop model refinement process. By synthesizing techniques from static and dynamic analysis, feedback-driven fuzzing, large language models, and code property graphs (CPGs), the study analyzes 55 high-quality research efforts, identifies five key open challenges, and proposes a unified research agenda for semantic-aware, feedback-driven, and multi-language-supported security testing frameworks.

adaptive testingCI/CDprogram analysis

This work addresses the fragility, inefficiency, and strong platform coupling commonly found in CI/CD pipelines for legacy COBOL systems, which often result in high maintenance costs and vendor lock-in. To overcome these challenges, the authors propose a portable CI/CD architecture tailored for highly secure and compliance-driven environments. The approach leverages OCI-compliant container images preloaded with COBOL toolchains, introduces a platform abstraction layer, integrates multiple repositories, and employs Groovy script refactoring to achieve platform-agnostic continuous integration and delivery. Empirical evaluation demonstrates that the proposed solution significantly enhances efficiency—reducing pipeline execution time by 82%—while simultaneously improving system portability, security, and maintainability. This architecture offers a reusable paradigm for modernizing legacy COBOL applications within regulated domains.

CI/CDCOBOLlegacy systems

This study addresses the significant abstraction gap between security-by-design specifications—typically expressed in domain-specific languages (DSLs)—and code-level analyzers, which impedes the traceability of design intent to implementation vulnerabilities. It presents the first large-scale empirical investigation, examining 559 security checks across 36 analyzers and 66 security design DSLs. The authors introduce SecLan, a unified model that captures shared security concepts between these two layers, and validate its structure through expert evaluation involving 22 practitioners and qualitative interviews with 9 additional experts. The findings reveal a pronounced mismatch between security concepts at the design and implementation levels, with existing analyzer checks often relying on overly broad vulnerability descriptions, leading to ambiguous mappings. This work provides both an empirical foundation and a modeling framework to bridge the gap between security design and implementation.

abstraction gapcode analyzersdomain-specific languages

Hot Scholars

LB

Luca Barletta

Politecnico di Milano
Communication TheoryInformation Theory
AB

Anita Burgun

Professor of Medical Informatics, Paris Descartes University
biomedical informatics
AM

Amin Milani Fard

Associate Professor at New York Institute of Technology - Vancouver, Canada
Software AnalysisSoftware EngineeringAI/MLSecurity and Privacy
JF

Jean-François Ethier

Prof. Titulaire, service de médecine interne, Université de Sherbrooke
Informatique Médicale: interopérabilitéontologiesrecherche translationnellemédecine
EV

Esther Villar-Rodriguez

Quantum Technologies, TECNALIA
Artificial IntelligenceMachine LearningQuantum Computing