Publication | Closed Access
How Developers Diagnose Potential Security Vulnerabilities with a Static Analysis Tool
46
Citations
52
References
2018
Year
Software MaintenanceEngineeringInformation SecuritySecurity DefectsSoftware EngineeringSource Code AnalysisSoftware AnalysisVulnerability Assessment (Computing)Defect ResolutionEmpirical Software Engineering ResearchSecurity ToolsSoftware PracticeStatic CheckingStatic AnalysisSecure By DesignComputer ScienceStatic Program AnalysisSoftware DesignSoftware SecurityProgram AnalysisSoftware TestingStatic Analysis ToolSystem Software
While using security tools to resolve security defects, software developers must apply considerable effort. Success depends on a developer's ability to interact with tools, ask the right questions, and make strategic decisions. To build better security tools and subsequently help developers resolve defects more accurately and efficiently, we studied the defect resolution process-from the questions developers ask to their strategies for answering them. In this paper, we report on an exploratory study with novice and experienced software developers. We equipped them with Find Security Bugs, a security-oriented static analysis tool, and observed their interactions with security vulnerabilities in an open-source system that they had previously contributed to. We found that they asked questions not only about security vulnerabilities, associated attacks, and fixes, but also questions about the software itself, the social ecosystem that built the software, and related resources and tools. We describe the strategic successes and failures we observed and how future tools can leverage our findings to encourage better strategies.
| Year | Citations | |
|---|---|---|
Page 1
Page 1