How Does Refactoring Impact Security When Improving Quality? A Security-Aware Refactoring Approach

How Does Refactoring Impact Security When Improving Quality? A Security-Aware Refactoring Approach
复制标题

DOI:
10.1109/tse.2020.3005995
复制
发表时间:
2020-06
影响因子:
7.4
通讯作者:
Chaima Abid;Marouane Kessentini;Vahid Alizadeh;Mouna Dhaouadi;R. Kazman
Chaima Abid;Marouane Kessentini;Vahid Alizadeh;Mouna Dhaouadi;R. Kazman
中科院分区:
计算机科学1区
文献类型:
--
作者:
Chaima Abid;Marouane Kessentini;Vahid Alizadeh;Mouna Dhaouadi;R. Kazman

文献摘要

被引文献

相似文献

虽然软件重构研究的最新发展使用各种质量属性来识别重构机会并评估重构建议,但在提高其他质量目标时重构对软件系统安全性的影响尚未得到充分探讨。了解系统在重构后如何抵抗安全风险以提高质量指标是至关重要的。例如,重构被广泛用于提高代码的可重用性,但是由于创建的抽象,这种改进可能会增加攻击面。在设计中增加安全关键类的分布以提高模块性可能会导致软件系统对攻击的弹性降低。在本文中,我们研究了提高不同质量属性(例如,可重用性、可扩展性等),根据QMOOD模型,在与数据访问相关的文献中定义的一组8个安全度量的有效性。我们还研究了不同重构对这些静态安全度量的影响。然后,我们提出了一个多目标重构推荐方法,找到质量属性和安全性之间的平衡的基础上的相关性结果,以指导搜索。我们在30个开源项目上评估了我们的工具。我们还收集了从业者对我们的工具推荐的重构的看法,这些重构对安全性和其他质量属性可能产生的影响。我们的研究结果证实,开发人员需要在重构软件系统时,由于它们之间的负相关性的安全性和其他质量之间进行权衡。
While state of the art of software refactoring research uses various quality attributes to identify refactoring opportunities and evaluate refactoring recommendations, the impact of refactoring on the security of software systems when improving other quality objectives is under-explored. It is critical to understand how a system is resistant to security risks after refactoring to improve quality metrics. For instance, refactoring is widely used to improve the reusability of code, however such an improvement may increase the attack surface due to the created abstractions. Increasing the spread of security-critical classes in the design to improve modularity may result in reducing the resilience of software systems to attacks. In this paper, we investigated the possible impact of improving different quality attributes (e.g., reusability, extendibility, etc.), from the QMOOD model, effectiveness on a set of 8 security metrics defined in the literature related to the data access. We also studied the impact of different refactorings on these static security metrics. Then, we proposed a multi-objective refactoring recommendation approach to find a balance between quality attributes and security based on the correlation results to guide the search. We evaluated our tool on 30 open source projects. We also collected the practitioner perceptions on the refactorings recommended by our tool in terms of the possible impact on both security and other quality attributes. Our results confirm that developers need to make trade-offs between security and other qualities when refactoring software systems due to the negative correlations between them.