Amit Seal Ami

CyberSecurity | Researcher | Ph. D. Candidate

I question assumptions made in the #infosec world.

For example, do security analysis techniques work as they claim? How do we evaluate security analysis techniques and figure out design/implementation flaws in them? Are they all designed with similar threat models in mind, or do they make implicit unaligned assumptions? So on and so forth.

Then, I make systematic evaluation frameworks for security techniques.

🎯

amitsealami.com/works

2023-08-13

lack of response, SAST developers' unwillingness to accept a flaw as an issue, NDA/confidentiality of product code, and lack of incentives.

6. Security, being a weak-linked software property, can only be holistically improved when SASTs focus on hard-to-find vulnerabilities, focusing more on reducing false negatives instead of inheriting the focus on reducing false positives from the program analysis domain.

7. That can only be done by raising awareness about Flaws in SASTs, aligning the design goals of SASTs with the goals of practitioners, designing evaluation protocol, and streamlining the false-negative reporting process.

8. The full paper, in both PDF and web-readable format, is available here! amitsealami.com/false-negative

2023-08-13

3. Furthermore, while participants described their strong preference towards security, the processes for selecting SASTs did not reflect such a strong preference. We identified two critical reasons based on our findings:

a. Lack of Motivation: practitioners often seemed unreasonably optimistic about SASTs' abilities, assuming that SASTs "just work."

b. Lack of Means: those who wanted to evaluate described the existing means, such as benchmarks, as biased and/or not representative of real, complex vulnerabilities.

4. Further, we report a critical paradox in SAST-related assumptions in practice. Participants expressed that they rely on SASTs to overcome the limitations (gap) of manual analysis and, at the same time, expect that manual analysis will cover the limitations (flaws) of SASTs.

5. Aggravatingly, even if practitioners find flaws, they are hesitant to report those flaws because of the experienced

2023-08-13

While we have been focusing on reducing false positives in vulnerability detection, my IEEE S&P'24 paper, in collaboration with Kevin Moran, Denys Poshyvanyk, and Adwait Nadkarni, shows the contrary: developers would rather have more false positives if the tool finds the vulnerabilities. FNs are of more concern to them. Key insights below:

1. While we found several insights that match existing literature, e.g., "Select situations can lead to the de-prioritization of software security," the rest challenge existing literature, identifying challenges that need attention from practitioners, SAST developers, and researchers.

2. For example, "Developer Happiness is Key" is the primary design goal of program analysis tools, thus focusing on reducing false positives in general. However, participants strongly favor reducing false negatives because "that one is going to kill you".

Further Key insights and the full paper are available below:

tags: #IEEESSP'24 #sp #security #sast #study #stem #WM

Amit Seal Ami boosted:
Metasecurity Solutionsmetasecsol@ioc.exchange
2023-07-26
Amit Seal Ami boosted:
2023-04-29

Great scoop by @kimzetter: DoJ, Mandiant and Microsoft stumbled upon the SolarWinds breach six months earlier than previously reported, but were unaware of the significance of what they had found.

Amazing this is only surfacing publicly now.

wired.com/story/solarwinds-hac

2023-01-01

Happy new year. :ablobcatattention:

Last year I did not do much. I hope I will do more this year.

Regardless, I pray that everyone around me will live happily, with sound health and with peace.

I pray the same for you. 🙏

#newyear #newyear2023

2022-12-21

@natedog nice! 😆

2022-12-21

Read this question earlier: "Can you name a famous horse without googling?"

---

me instantly: TROJAN HORSE 🙋‍♂️
also me: But.. that's not an actual horse 🤦‍♂️
then me: Still a horse! 🤷‍♂️

I sure hope I am not the only one who went through this route of thinking.

2022-12-21

Nothing against the individual in this filter, to be honest. But I was being bombarded with news and articles about him in my news feed, here, and elsewhere. I am glad if you want to discuss about things he has been doing, but I am not really interested to know about this person any more.

2022-12-21

This is a lifesaver in Mastodon!

Instant sanitization of my mastodon feed. 🙏🏼

Sharing this in case someone else needs it.

Shows screenshot of mastodon keyword filter. The title is "Elon Musk". There is only one keyword in this list, "Elon Musk". The filter is applied to Home and lists, Notifications, Public timelines, Conversations, Profiles.
2022-12-06

@nixCraft I know some people who made some scripts to automatically add and remove space and commit it, just to increase their commit counts ...

Amit Seal Ami boosted:
Micah Leemicahflee
2022-11-12

This post is good. Read it, especially if you're just joining Mastodon from Twitter hughrundle.net/home-invasion/

2022-11-08
Amit Seal Ami boosted:
Lukasz OlejnikLukaszOlejnik
2022-11-07
2022-11-06

@ishtiaque  Nice to see you here! :) 👋🏼

2022-11-06

@matthew_d_green Ah, that might be why Twitter is also blocking links to ioc.exchange when I tried to share earlier.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst