FSE 2026
Sun 5 - Thu 9 July 2026 Montreal, Canada
Thu 9 Jul 2026 10:30 - 10:40 at MB 3.435 - Software Security Chair(s): Kevin Leach

We present FISTS, a tool that enables security testing of configuration updates in software-defined networks (SDNs). In contrast to conventional approaches, which are model-based and coupled to a specific SDN system, FISTS is entirely black-box thus enabling testing of different platforms, which is necessary for most industries since they typically use proprietary SDN frameworks.

FISTS works by probing the hosts on a network before and after an SDN reconfiguration, automatically identifying corresponding nodes, and determining their port state change; finally, it leverages anomaly detection algorithms to prioritize the inspection of hosts data. FISTS also enable engineers to minimize the number of inspected nodes while maximizing the vulnerabilities found by avoiding the inspection of consecutive false alarms.

We have evaluated FISTS on 220 new and unique datasets based on distinct configuration scenarios; our results show that FISTS leads to best results (up to 0.99 recall) with COF and HBOS, but KNN leads to close recall and minimal execution time. Further, it enables detecting all vulnerable hosts by inspecting less than 10% of the monitored data.

A demo of FISTS is available online at the following URL: https:// youtu.be/UIMwFqAvAXg. The tool is available (open surce) at: https: //doi.org/10.5281/zenodo.18201382.

Thu 9 Jul

Displayed time zone: Eastern Time (US & Canada) change

10:30 - 12:30
10:30
10m
Talk
FISTS: A Field-based Security Testing Tool for Updates in Software-Defined Networks
Tool Demonstrations
Jahanzaib MALIK University of Luxembourg, Fabrizio Pastore University of Luxembourg
DOI Pre-print Media Attached File Attached
10:40
20m
Talk
Enabling Security Champions With Breakout Action Groups (BAGs) – A Longitudinal Case Study
Industry Papers
Jens Christian Opdenbusch Ruhr University Bochum, Sangavi Shanthakumar Ruhr University Bochum, Martina Angela Sasse Ruhr University Bochum, Marco Gutfleisch LMU Munich
11:00
20m
Talk
An Empirical Evaluation of Generative AI in Security Requirements Engineering and Threat Modeling
Industry Papers
Francis Martins UNB, Elaine Venson University of Brasilia
11:20
20m
Talk
Uncovering Similar but Different Packages in PyPI and Potential Security Threats
Research Papers
Sunha Park Korea University, Soojin Han Dongduk Women's University, Seunghoon Woo Korea University
Pre-print
11:40
20m
Talk
BackportBench: A Multilingual Benchmark for Automated Patch Backporting
Research Papers
Zhiqing Zhong The Chinese University of Hong Kong, Shenzhen (CUHK-Shenzhen), Jiaming Huang The Chinese University of Hong Kong, Shenzhen (CUHK-Shenzhen), Pinjia He Chinese University of Hong Kong, Shenzhen
Pre-print
12:00
10m
Talk
BackportCheck: An Open-Source Tool to Support Backport Decisions in Large Software Ecosystems
Tool Demonstrations
Salma Sghaier ENSI, Mannouba University, Mohamed Anas Daoud ENSI, Mannouba University, Marouene Chaieb National School of Computer Science, Moataz Chouchen Concordia University, Mohammad Hamdaqa Polytechnique Montreal, Mohamed Wiem Mkaouer University of Michigan-Flint
12:10
10m
Short-paper
Towards Predicting Multi-Vulnerability Attack Chains in Software Supply Chains from Software Bill of Materials Graphs
Ideas, Visions and Reflections
Laura Baird University of Colorado Colorado Springs (UCCS), Armin Moin Purdue University
DOI