Our work, “Achilles’ Heel of Plug-and-Play Software Architectures: A Grounded Theory Based Approach”, was published in 2019 ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering.
Publication details, authors, citation information, and available resources are provided below.
@inproceedings{santos2019achilles,
author = {Santos, Joanna C. S. and Sejfia, Adriana and Corrello, Taylor and Gadenkanahalli, Smruthi and Mirakhorli, Mehdi},
title = {Achilles’ Heel of Plug-and-Play Software Architectures: A Grounded Theory Based Approach},
year = {2019},
isbn = {9781450355728},
publisher = {Association for Computing Machinery},
address = {New York, NY, USA},
url = {https://doi.org/10.1145/3338906.3338969},
doi = {10.1145/3338906.3338969},
abstract = {Through a set of well-defined interfaces, plug-and-play architectures enable additional functionalities to be added or removed from a system at its runtime. However, plug-ins can also increase the application’s attack surface or introduce untrusted behavior into the system. In this paper, we (1) use a grounded theory-based approach to conduct an empirical study of common vulnerabilities in plug-and-play architectures; (2) conduct a systematic literature survey and evaluate the extent that the results of the empirical study are novel or supported by the literature; (3) evaluate the practicality of the findings by interviewing practitioners with several years of experience in plug-and-play systems. By analyzing Chromium, Thunderbird, Firefox, Pidgin, WordPress, Apache OfBiz, and OpenMRS, we found a total of 303 vulnerabilities rooted in extensibility design decisions and observed that these plugin-related vulnerabilities were caused by 16 different types of vulnerabilities. Out of these 16 vulnerability types we identified 19 mitigation procedures for fixing them. The literature review supported 12 vulnerability types and 8 mitigation techniques discovered in our empirical study, and indicated that 5 mitigation techniques were not covered in our empirical study. Furthermore, it indicated that 4 vulnerability types and 11 mitigation techniques discovered in our empirical study were not covered in the literature. The interviews with practitioners confirmed the relevance of the findings and highlighted ways that the results of this empirical study can have an impact in practice.},
booktitle = {Proceedings of the 2019 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering},
pages = {671–682},
numpages = {12},
keywords = {Software Security, Plug-and-Play Design, Vulnerabilities},
location = {Tallinn, Estonia},
series = {ESEC/FSE 2019}
}
Subscribe to this blog via RSS.
Paper 37
Research 37
Tool 2
Llm 10
Dataset 2
Survey 1
InstruMate: A Systematic Framework for Assessing Android App Repackaging Resilience
Posted on 01 Jan 2026Paper (37) Research (37) Tool (2) Llm (10) Dataset (2) Qualitative-analysis (1) Survey (1)