Barriers to Shift-Left Security: The Unique Pain Points of Writing Automated Tests Involving Security Controls

Barriers to Shift-Left Security: The Unique Pain Points of Writing Automated Tests Involving Security Controls
复制标题

DOI:
10.1145/3475716.3475786
复制
发表时间:
2021-10
期刊:
Proceedings of the 15th ACM / IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM)
影响因子:
--
通讯作者:
Danielle Gonzalez;P. Perez;Mehdi Mirakhorli
Danielle Gonzalez;P. Perez;Mehdi Mirakhorli
中科院分区:
其他
文献类型:
--
作者:
Danielle Gonzalez;P. Perez;Mehdi Mirakhorli

文献摘要

相似文献

背景资料:自动化的单元和集成测试允许软件开发团队不断地评估他们的应用程序的行为,并确保满足需求。随着越来越多的团队开始将安全性保留在工作流中,对在单元和集成级别显式测试安全性的兴趣也在增加,但是对于开发人员在学习调整现有技能以编写这些测试时可能遇到的任何潜在痛点,几乎没有什么深入了解。目标:确定安全单元和集成测试的痛点,这些痛点可能会对将安全(测试)转移到该级别的工作产生负面影响。方法:对525个与安全单元和集成测试相关的Stack Overflow和Security Stack Exchange职位进行了混合方法实证研究。应用潜在狄利克雷分配(LDA)来识别共同讨论的主题,通过定性分析来了解痛点,并分析链接以研究共同共享的资源。结果:确定了代表安全控制、组件和场景的九个主题;身份验证是最常测试的控制。开发人员经历了安全单元和集成测试特有的七个痛点,这些痛点都受到安全控制设计和实现的复杂性的影响。大多数链接的资源是其他问答帖子,但安全工具和库的存储库和文档也很常见。结论:当在这个级别编写涉及安全控制的测试时,开发人员可能会遇到几个独特的痛点。需要额外的资源来指导开发人员应对这些挑战,这也应该影响策略和工具的创建,以帮助将安全测试转移到这一级别。为了加速这一点,强调了基于这些研究结果的从业者和未来研究方向的可行性建议。
Background: Automated unit and integration tests allow software development teams to continuously evaluate their application's behavior and ensure requirements are satisfied. Interest in explicitly testing security at the unit and integration levels has risen as more teams begin to shift security left in their workflows, but there is little insight into any potential pain points developers may experience as they learn to adapt their existing skills to write these tests. Aims: Identify security unit and integration testing pain points that could negatively impact efforts to shift security (testing) left to this level. Method: An mixed-method empirical study was conducted on 525 Stack Overflow and Security Stack Exchange posts related to security unit and integration testing. Latent Dirichlet Allocation (LDA) was applied to identify commonly discussed topics, pain points were learned through qualitative analysis, and links were analyzed to study commonly-shared resources. Results: Nine topics representing security controls, components, and scenarios were identified; Authentication was the most commonly tested control. Developers experienced seven pain points unique to security unit and integration testing, which were all influenced by the complexity of security control designs and implementations. Most linked resources were other Q&A posts, but repositories and documentation for security tools and libraries were also common. Conclusions: Developers may experience several unique pain points when writing tests at this level involving security controls. Additional resources are needed to guide developers through these challenges, which should also influence the creation of strategies and tools to help shift security testing to this level. To accelerate this, actionable recommendations for practitioners and future research directions based on these findings are highlighted.