The Case for Adaptive Security Interventions

The Case for Adaptive Security Interventions
复制标题

DOI:
10.1145/3471930
复制
发表时间:
2021-06
期刊:
ACM Trans. Softw. Eng. Methodol.
影响因子:
--
通讯作者:
I. Rauf;M. Petre;T. Tun;Tamara Lopez;Paul Lunn;D. Linden;J. Towse;H. Sharp;M. Levine;A. Rashid;B. Nuseibeh
I. Rauf;M. Petre;T. Tun;Tamara Lopez;Paul Lunn;D. Linden;J. Towse;H. Sharp;M. Levine;A. Rashid;B. Nuseibeh
中科院分区:
其他
文献类型:
--
作者:
I. Rauf;M. Petre;T. Tun;Tamara Lopez;Paul Lunn;D. Linden;J. Towse;H. Sharp;M. Levine;A. Rashid;B. Nuseibeh

文献摘要

被引文献

相似文献

尽管有各种方法和工具可以促进安全编码,但开发人员继续编写包含常见漏洞的代码。理解为什么技术进步并不能充分促进开发人员编写安全代码是很重要的。为了扩大我们对开发人员行为的理解,我们使用认知和社会心理学理论考虑了开发人员安全决策空间的复杂性。我们在本文中报告的跨学科研究(1)借鉴心理学文献,为实现安全目标的三种障碍提供概念基础,(2)报告对现有软件安全文献的深入元分析,确定了影响开发人员安全决策的因素目录,以及(3)描述在编码期间开发人员可用的现有安全干预的情况,并识别差距。总的来说,这些情况表明,阻碍实现安全目标的不同形式的障碍是由不同的促成因素造成的。如果干预措施更敏感地反映心理因素,并将技术复杂性,心理框架和可用性结合起来,干预措施将更加有效。我们的分析表明,“自适应安全干预”作为一种解决方案,响应不断变化的安全需求的个人开发人员和一个目前的概念验证工具,以证实我们的建议。
Despite the availability of various methods and tools to facilitate secure coding, developers continue to write code that contains common vulnerabilities. It is important to understand why technological advances do not sufficiently facilitate developers in writing secure code. To widen our understanding of developers' behaviour, we considered the complexity of the security decision space of developers using theory from cognitive and social psychology. Our interdisciplinary study reported in this article (1) draws on the psychology literature to provide conceptual underpinnings for three categories of impediments to achieving security goals, (2) reports on an in-depth meta-analysis of existing software security literature that identified a catalogue of factors that influence developers' security decisions, and (3) characterises the landscape of existing security interventions that are available to the developer during coding and identifies gaps. Collectively, these show that different forms of impediments to achieving security goals arise from different contributing factors. Interventions will be more effective where they reflect psychological factors more sensitively and marry technical sophistication, psychological frameworks, and usability. Our analysis suggests “adaptive security interventions” as a solution that responds to the changing security needs of individual developers and a present a proof-of-concept tool to substantiate our suggestion.