Developers Need Support, Too: A Survey of Security Advice for Software Developers

被引:73
作者
Acar, Yasemin [1 ]
Stransky, Christian [2 ]
Wermke, Dominik [1 ]
Weir, Charles [3 ]
Mazurek, Michelle L. [4 ]
Fahl, Sascha [1 ]
机构
[1] Leibniz Univ Hannover, Hannover, Germany
[2] Univ Saarland, CISPA, Saarbrucken, Germany
[3] Secur Lancaster, Lancaster, PA USA
[4] Univ Maryland, College Pk, MD 20742 USA
来源
2017 IEEE CYBERSECURITY DEVELOPMENT (SECDEV) | 2017年
关键词
D O I
10.1109/SecDev.2017.17
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Increasingly developers are becoming aware of the importance of software security, as frequent high-profile security incidents emphasize the need for secure code. Faced with this new problem, most developers will use their normal approach: web search. But are the resulting web resources useful and effective at promoting security in practice? Recent research has identified security problems arising from Q&A resources that help with specific secure-programming problems, but the web also contains many general resources that discuss security and secure programming more broadly, and to our knowledge few if any of these have been empirically evaluated. The continuing prevalence of security bugs suggests that this guidance ecosystem is not currently working well enough: either effective guidance is not available, or it is not reaching the developers who need it. This paper takes a first step toward understanding and improving this guidance ecosystem by identifying and analyzing 19 general advice resources. The results identify important gaps in the current ecosystem and provide a basis for future work evaluating existing resources and developing new ones to fill these gaps.
引用
收藏
页码:22 / 26
页数:5
相关论文
共 13 条
[1]  
Acar Y, 2016, P 37 IEEE S SEC PRIV
[2]  
[Anonymous], CONTENT ANAL INTRO I
[3]  
[Anonymous], 2017, P 38 IEEE S SEC PRIV
[4]   Improving App Privacy: Nudging App Developers to Protect User Privacy [J].
Balebako, Rebecca ;
Cranor, Lorrie .
IEEE SECURITY & PRIVACY, 2014, 12 (04) :55-58
[5]  
Bureau of Labor Statistics, 2016, OCC EMPL STAT
[6]  
Fahl S., 2013, CCS
[7]  
Fahl S., 2013, P 9 S US PRIV SEC SO
[8]  
Fischer F., 2017, P 38 IEEE S SEC PRIV
[9]  
Morgan S., 2016, TOP 2016 CYBERSECURI
[10]  
Nadi S., 2016, P 37 IEEE ACM INT C