People / Faculty / Laurie Williams

Laurie Williams

  • Goodnight Distinguished University Professor
Profile photo of Laurie Williams

Bio

Laurie Williams is a Goodnight Distinguished University Professor in the Computer Science Department of the College of Engineering at North Carolina State University (NCSU). Laurie is a co-director of the NCSU Secure Computing Institute (SCI) and the NCSU Science of Security Lablet. Laurie’s research focuses on software security and secure software supply chain. She is an associate editor-in-chief of the IEEE Security and Privacy magazine. Laurie is an IEEE Fellow and an ACM Fellow. Laurie has a BS in Industrial Engineering from Lehigh University, an MBA from Duke University, and a PhD in Computer Science from the University of Utah.

Publications

  • Imranur Rahman, Jill Marley, William Enck, and Laurie Williams, Which Is Better For Reducing Outdated And Vulnerable Dependencies: Pinning Or Floating?, in Proceedings of the IEEE/ACM International Conference on Automated Software Engineering, Nov. 2025.
  • Mahzabin Tamanna, Yash Chandrani, Matthew Burrows, Brandon Wroblewski, Laurie Williams, and and Dominik Wermke, Your Build Scripts Stink: The State of Code Smells in Build Scripts, in Proceedings of the 40th IEEE/ACM International Conference on Automated Software Engineering (ASE), Nov. 2025.
  • Lorenzo Neil, Deepthi Mungara, Laurie Williams, Yasemin Acar, and Bradley Reaves, It Should Be Easy but... New Users’ Experiences and Challenges with Secret Management Tools, in Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS), Nov. 2025, pp. 2519–2533.
    [PDF]
  • Md Rayhanur Rahman, Setu Kumar Basak, Rezvan Mahdavi Hezaveh, and Laurie Williams, SoK: An Empirical Investigation of Malware Techniques in Advanced Persistent Threat Attacks, Computers & Security, vol. 157, p. 104618, Oct. 2025.
    [PDF]
  • Md Rayhanur Rahman, Imranur Rahman, and Laurie Williams, If you cannot Measure it, you cannot Secure it. A Case Study on Metrics for Informed Choice of Security Controls, Journal of Information Security and Applications, vol. 92, Jul. 2025.
  • Md Rayhanur Rahman, Brandon Wroblewski, Quinn Matthews, Brantley Morgan, Timothy Menzies, and Laurie Williams, Mining Temporal Attack Patterns from Cyberthreat Intelligence Reports, Knowledge and Information Systems, vol. 67, pp. 8941–8981, Jul. 2025.
    [PDF]
  • Laurie Williams, Giacomo Benedetti, Sivana Hamer, Ranindya Paramitha, Imranur Rahman, Mahzabin Tamanna, Greg Tystahl, Nusrat Zahan, Patrick Morrison, Yasemin Acar, Michel Cukier, Christian Kästner, Alexandros Kapravelos, Dominik Wermke, and William Enck, Research Directions in Software Supply Chain Security, ACM Transactions on Software Engineering Methodology (TOSEM), pp. 1–38, May 2025.
    [PDF]
  • Sivana Hamer, Nasif Imtiaz, Mahzabin Tamanna, Preya Shabrina, and Laurie Williams, Trusting code in the wild: Exploring contributor reputation measures to review dependencies in the Rust ecosystem, IEEE Transactions on Software Engineering (TSE), vol. 51, no. 4, Apr. 2025.
  • Setu Kumar Basak, K. Virgil English, Ken Ogura, Vitesh Kambara, Bradley Reaves, and Laurie Williams, AssetHarvester: A Static Analysis Tool for Detecting Secret-Asset Pairs in Software Artifacts, in Proceedings of the International Conference on Software Engineering (ICSE), Apr. 2025.
  • Nusrat Zahan, Philipp Burckhardt, Mikola Lysenko, Feross Aboukhadijeh, and Laurie Williams, Leveraging Large Language Models to Detect npm Malicious Packages, in Proceedings of the IEEE/ACM International Conference on Software Engineering (ICSE), Apr. 2025.
  • Setu Kumar Basak, K. Virgil English, Ken Ogura, Vitesh Kambara, Bradley Reaves, and Laurie Williams, AssetHarvester: A Static Analysis Tool for Detecting Secret-Asset Pairs in Software Artifacts, in Proceedings of the IEEE/ACM International Conference on Software Engineering (ICSE), Apr. 2025, pp. 1268–1280.
    [PDF]
  • Aishwarya Seth, Saikath Bhattacharya, Sarah Elder, Nusrat Zahan, and Laurie Williams, Comparing Effectiveness and Efficiency of Interactive Application Security Testing (IAST) and Runtime Application Self-Protection (RASP) Tools in a Large Java-based System, Empirical Software Engineering, vol. 30, no. 67, Feb. 2025.
  • Md Rayhanur Rahman, Brandon Wroblewski, Mahzabin Tamanna, Imranur Rahman, Andrew Anufryienak, and Laurie Williams, Towards a Taxonomy of Challenges in Security Control Implementation, in Proceedings of the Annual Computer Security Applications Conference (ACSAC), Dec. 2024, pp. 61–75.
  • Nusrat Zahan, Yasemin Acar, Michel Cukier, William Enck, Alexandros Kapravelos, Christian Kästner, Dominik Wermke, and Laurie Williams, S3C2 Summit 2023-11: Industry Secure Supply Chain Summit. Aug-2024. arXiv:2408.16529.
    [PDF]
  • Sivana Hamer, Marcelo d’Amorim, and Laurie Williams, Just another copy and paste? Comparing the security vulnerabilities of ChatGPT generated code and StackOverflow answers, in Proceedings of the IEEE Deep Learning Security and Privacy Workshop, co-located with IEEE S&P, May 2024, pp. 87–94.
  • Greg Tystahl, Yasemin Acar, Michel Cukier, William Enck, Alexandros Kapravelos, Christian Kästner, Dominik Wermke, and Laurie Williams, S3C2 Summit 2024-03: Industry Secure Supply Chain Summit. May-2024. arXiv:2405.08762.
    [PDF]
  • Sarah Elder, Md Rayhanur Rahman, Gage Fringer, Kunal Kapoor, and Laurie Williams, A Survey on Software Vulnerability Exploitability Assessment, ACM Comput. Surv., vol. 56, no. 8, Apr. 2024.
    [PDF]
  • Nusrat Zahan, Philipp Burckhardt, Mikola Lysenko, Feross Aboukhadijeh, and Laurie Williams, MalwareBench: Malware samples are not enough, in 2024 IEEE/ACM 21st International Conference on Mining Software Repositories (MSR), Apr. 2024, pp. 728–732.
  • Laurie Williams, Narrowing the Software Supply Chain Attack Vectors: The SSDF Is Wonderful but not Enough, IEEE Security & Privacy, vol. 22, no. 2, pp. 4–7, 2024.
  • William Enck, Yasemin Acar, Michel Cukier, Alexandros Kapravelos, Christian Kästner, and Laurie Williams, S3C2 Summit 2023-06: Government Secure Supply Chain Summit. Aug-2023. arXiv:2308.06850.
    [PDF]
  • Trevor Dunlap, Yasemin Acar, Michel Cucker, William Enck, Alexandros Kapravelos, Christian Kastner, and Laurie Williams, S3C2 Summit 2023-02: Industry Secure Supply Chain Summit. Jul-2023. arXiv:2307.16557.
    [PDF]
  • Mindy Tran, Yasemin Acar, Michel Cucker, William Enck, Alexandros Kapravelos, Christian Kastner, and Laurie Williams, S3C2 Summit 2022-09: Industry Secure Suppy Chain Summit. Jul-2023. arXiv:2307.15642.
    [PDF]
  • Nusrat Zahan, Shohanuzzaman Shohan, Dan Harris, and Laurie Williams, Do Software Security Practices Yield Fewer Vulnerabilities?, in 2023 IEEE/ACM 45th International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP), May 2023, pp. 292–303.
  • Nusrat Zahan, Elizabeth Lin, Mahzabin Tamanna, William Enck, and Laurie Williams, Software Bills of Materials Are Required. Are We There Yet?, IEEE Security and Privacy Magazine, vol. 21, no. 2, pp. 82–88, Mar. 2023. (column).
  • Nusrat Zahan, Parth Kanakiya, Brian Hambleton, Shohanuzzaman Shohan, and Laurie Williams, Openssf scorecard: On the path toward ecosystem-wide automated security metrics, IEEE Security & Privacy, vol. 21, no. 6, pp. 76–88, 2023.
  • Nasif Imtiaz and Laurie Williams, Are your dependencies code reviewed?: Measuring code review coverage in dependency updates, IEEE Transactions on Software Engineering, 2023.
  • Carl Landwehr, Michael K Reiter, Laurie Williams, Gene Tsudik, Trent Jaeger, Tadayoshi Kohno, and Apu Kapadia, Looking Backwards (and Forwards): NSF Secure and Trustworthy Computing 20-Year Retrospective Panel Transcription, IEEE Security & Privacy, vol. 21, no. 2, pp. 32–42, 2023.
  • Md Rayhanur Rahman, Rezvan Mahdavi Hezaveh, and Laurie Williams, What are the attackers doing now? Automating cyberthreat intelligence extraction from text on pace with the changing threat landscape: A survey, ACM Computing Surveys, vol. 55, no. 12, pp. 1–36, 2023.
  • Setu Kumar Basak, Jamison Cox, Bradley Reaves, and Laurie Williams, A Comparative Study of Software Secrets Reporting by Secret Detection Tools, in 2023 ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM), 2023, pp. 1–12.
  • Eric Bodden, Sam Weber, and Laurie Williams, Empirical Evaluation of Secure Development Processes (Dagstuhl Seminar 23181), Dagstuhl Reports, vol. 13, no. 5, pp. 1–21, 2023.
    [PDF]
  • Sarah Elder, Nusrat Zahan, Rui Shu, Monica Metro, Valeri Kozarev, Tim Menzies, and Laurie A. Williams, Do I really need all this work to find vulnerabilities?, Empirical Software Engineering, vol. 27, Nov. 2022.
  • Setu Kumar Basak, Lorenzo Neil, Bradley Reaves, and Laurie A. Williams, What are the Practices for Secret Management in Software Artifacts?, in Proceedings of the IEEE Secure Development Conference (SecDev), Oct. 2022.
  • Laurie A. Williams, Trusting Trust: Humans in the Software Supply Chain Loop, IEEE Security and Privacy Magazine, vol. 20, Sep. 2022.
  • Rezvan Mahdavi-Hezaveh, Nirav Ajmeri, and Laurie A. Williams, Feature toggles as code: Heuristics and metrics for structuring feature toggles, Information and Software Technology, vol. 145, May 2022.
  • Md. Rayhanur Rahman, Nasif Imtiaz, Margaret-Anne D. Storey, and Laurie A. Williams, Why secret detection tools are not enough: It’s not just about false positives - An industrial case study, Empirical Software Engineering, vol. 27, May 2022.
  • Rui Shu, Tianpei Xia, Laurie A. Williams, and Tim Menzies, Dazzle: Using Optimized Generative Adversarial Networks to Address Security Data Class Imbalance Issue, in Proceedings of the 19th International Conference on Mining Software Repositories, May 2022.
  • Nusrat Zahan, Thomas Zimmermann, Patrice Godefroid, Brendan Murphy, Chandra Shekhar Maddila, and Laurie A. Williams, What are Weak Links in the npm Supply Chain?, in Proceedings of the 44th International Conference on Software Engineering: Software Engineering in Practice, May 2022.
  • William Enck and Laurie Williams, Top Five Challenges in Software Supply Chain Security: Observations From 30 Industry and Government Organizations, IEEE Security and Privacy Magazine, vol. 20, no. 2, pp. 96–100, Mar. 2022. (column).
  • Charles Weir, Sammy Migues, and Laurie A. Williams, Exploring the Shift in Security Responsibility, IEEE Security and Privacy Magazine, vol. 20, Feb. 2022.
  • Rui Shu, Tianpei Xia, Laurie A. Williams, and Tim Menzies, Omni: automated ensemble with unexpected models against adversarial evasion attack, Empirical Software Engineering, vol. 27, Jan. 2022.
  • Nasif Imtiaz, Aniqa Khanom, and Laurie Williams, Open or sneaky? fast or slow? light or heavy?: Investigating security releases of open source packages, IEEE Transactions on Software Engineering, vol. 49, no. 4, pp. 1540–1560, 2022.
  • Nasif Imtiaz, Seaver Thorn, and Laurie A. Williams, A comparative study of vulnerability reporting by software composition analysis tools, in Proceedings of the 15th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM), Oct. 2021.
  • Saikath Bhattacharya, Munindar P. Singh, and Laurie A. Williams, Software Security Readiness and Deployment, in IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW), Oct. 2021.
  • Charles Weir, Sammy Migues, Mike Ware, and Laurie A. Williams, Infiltrating security into development: exploring the world’s largest software security study, in Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, Aug. 2021.
  • Laurie A. Williams, The People Who Live in Glass Houses Are Happy the Stones Weren’t Thrown at Them [From the Editors], IEEE Security and Privacy Magazine, vol. 19, May 2021.
  • Rui Shu, Tianpei Xia, Jianfeng Chen, Laurie Williams, and Tim Menzies, How to Better Distinguish Security Bug Reports (Using Dual Hyperparameter Optimization), Empirical Software Engineering, vol. 26, Apr. 2021.
  • Rayhanur Rahman, Christopher Parnin, and Laurie Williams, Security Smells in Ansible and Chef Scripts: A Replication Study, ACM Transactions on Software Engineering (TOSEM), vol. 20, no. 1, Jan. 2021.
  • Rayhanur Rahman, William Enck, and Laurie Williams, Do Configuration Management Tools Make Systems More Secure? An Empirical Research Plan, in Proceedings of the Symposium and Bootcamp on the Science of Security (HotSoS) Poster Session, Sep. 2020.
  • Christopher Theisen and Laurie Williams, Better together: Comparing vulnerability prediction models, Information and Software Technology, vol. 119, Mar. 2020.
    [PDF]
  • Hui Guo, Özgür Kafali, Anne-Liz Jeukeng, Laurie Williams, and Munindar P. Singh, Çorba: crowdsourcing to obtain requirements from regulations and breaches, Empirical Software Engineering, vol. 25, no. 1, pp. 532–561, 2020.
  • Zhe Yu, Christopher Theisen, Laurie A. Williams, and Tim Menzies, Improving vulnerability inspection efficiency using active learning, IEEE Transactions on Software Engineering, vol. 47, Oct. 2019.
  • Nasif Imtiaz, Brendan Murphy, and Laurie Williams, How Do Developers Act on Static Analysis Alerts? An Empirical Study of Coverity Usage, in Proceedings of the IEE International Symposium on Software Reliability Engineering (ISSRE), Oct. 2019, pp. 323–333.
    [PDF]
  • Inger Anne Tøndel, Martin Gilje Jaatun, Daniela Soares Cruzes, and Laurie Williams, Collaborative security risk estimation in agile software development, Information and Computer Security, vol. 27, no. 4, pp. 508–535, Sep. 2019.
    [PDF]
  • Md. Rayhanur Rahman, Akond Rahman, and Laurie Williams, Share, But be Aware: Security Smells in Python Gists, in Proceedings of the IEEE International Conference on Software Maintenance and Evolution (ICSME), Sep. 2019, pp. 536–540.
    [PDF]
  • Nuthan Munaiah, Akond Rahman, Justin Pelletier, Laurie Williams, and Andrew Meneely, Characterizing Attacker Behavior in a Cybersecurity Penetration Testing Competition, in Proceedings of the ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM), Sep. 2019, pp. 1–6.
    [PDF]
  • Laurie Williams, Science Leaves Clues, IEEE Security & Privacy Magazine, vol. 17, no. 5, pp. 4–6, 2019. (column).