Influences of developers' perspectives on their engagement with security in code

Influences of developers' perspectives on their engagement with security in code
复制标题

开发人员的观点对其参与代码安全性的影响

DOI:
10.1145/3528579.3529180
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
Rauf I
Rauf I
中科院分区:
--
文献类型:
--
作者:
Rauf I

文献摘要

参考文献

被引文献

相似文献

背景:最近的研究表明,安全编码不仅与技术要求有关,而且与开发人员的行为有关。目的:为了了解社会技术环境对开发人员如何关注和参与代码安全的影响,软件工程研究人员与社会心理学家合作进行了一项心理知情的研究。方法:在一项预先注册、组间、对照的实验中,来自多个自由职业社区的124名开发人员被准备好三种身份中的一种,然后他们以开放式回答完成代码审查任务。对丰富数据的定性分析集中于影响他们对代码安全问题识别的态度和推理。结果:总体来说,对代码安全的关注是断断续续的,焦点是不同的。虽然社交身份启动没有显著改变代码审查,但定性分析表明,开发人员在如何发现代码中的问题、如何解决这些问题以及如何证明自己的选择是合理的方面存在差异。结论:我们发现许多开发人员确实考虑了安全性-但彼此不同。因此,促进安全编码的有效干预措施必须适合个人发展背景。数据上载地址:https://osf.io/3jvrk
Background: Recent studies show that secure coding is about not only technical requirements but also developers' behaviour.Objective: To understand the influence of socio-technical contexts on how developers attend to and engage with security in code, software engineering researchers collaborated with social psychologists on a psychologically-informed study.Method: In a preregistered, between-group, controlled experiment, 124 developers from multiple freelance communities, were primed toward one of three identities, following which they completed code review tasks with open-ended responses. Qualitative analysis of the rich data focused on the attitudes and reasoning that shaped their identification of security issues within code.Results: Overall, attention to code security was intermittent and heterogeneous in focus. Although social identity priming did not significantly change the code review, qualitative analysis revealed that developers varied in how they noticed issues in code, how they addressed them, and how they justified their choices.Conclusion: We found that many developers do think about security - but differently from one another. Hence, effective interventions to promote secure coding must be appropriate to the individual development context. Data is uploaded at: https://osf.io/3jvrk
DOI: --
发表时间: 2022
期刊:
影响因子: --
作者:
I. Rauf;Tamara Lopez;Helen Sharp;M. Petre
通讯作者: M. Petre
软件工程中的开放科学
DOI: 10.1007/978-3-030-32489-6_17
发表时间: 2019
期刊: Proceedings of the 25th International Symposium on Software Testing and Analysis
影响因子: --
作者:
Daniel Méndez Fernández;D. Graziotin;S. Wagner;H. Seibold
通讯作者: H. Seibold
安全开发人员与 GitHub 用户的研究:探索便捷示例
DOI: --
发表时间: 2017
期刊: Symposium On Usable Privacy and Security
影响因子: --
作者:
Y. Acar;Christian Stransky;Dominik Wermke;Michelle L. Mazurek;S. Fahl
通讯作者: S. Fahl
网络安全知识体系
DOI: --
发表时间: 2017
期刊: International Symposium on Cloud and Service Computing
影响因子: --
作者:
Evon M. O. Abu
通讯作者: Evon M. O. Abu
DOI: 10.1111/glob.12051
发表时间: 2015-04-01
影响因子: 2.4
作者:
Beerepoot, Niels;Lambregts, Bart
通讯作者: Lambregts, Bart