"False negative - that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security Testing
Amit Seal Ami, Kevin Moran, Denys Poshyvanyk, Adwait Nadkarni
Abstract
The demand for automated security analysis techniques, such as static analysis based security testing (SAST) tools continues to increase. To develop SASTs that are effectively leveraged by developers for finding vulnerabilities, researchers and tool designers must understand how developers perceive, select, and use SASTs, what they expect from the tools, whether they know of the limitations of the tools, and how they address those limitations. This paper describes a qualitative study that explores the assumptions, expectations, beliefs, and challenges experienced by developers who use SASTs. We perform in-depth, semi-structured interviews with 20 practitioners who possess a diverse range of software development expertise, as well as a variety of unique security, product, and organizational backgrounds. We identify 17 key findings that shed light on developer perceptions and desires related to SASTs, and also expose gaps in the status quo – challenging long-held beliefs in SAST design priorities. Finally, we provide concrete future directions for researchers and practitioners rooted in an analysis of our findings.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers12
- Systematically Detecting Packet Validation Vulnerabilities in Embedded Network StacksPaschal C. Amusuo, Ricardo Andrés Calvo Méndez, Zhongwei Xu, Aravind Machiry et al.ASE 2023 · 9 citations
- On Prescription or Off Prescription? An Empirical Study of Community-Prescribed Security Configurations for KubernetesShazibul Islam Shamim, Hanyang Hu, Akond RahmanICSE 2025 · 4 citations
- LineBreaker: Finding Token-Inconsistency Bugs with Large Language ModelsHongbo Chen, Yifan Zhang, Xing Han, Tianhao Mao et al.ASE 2025 · 3 citations
- Understanding Industry Perspectives of Static Application Security Testing (SAST) EvaluationYuan Li, Peisen Yao, Kan Yu, Chengpeng Wang et al.FSE 2025 · 1 citation
- AutoBaxBuilder: Bootstrapping Code Security BenchmarkingTobias von Arx, Niels Mündler, Mark Vero, Maximilian Baader et al.ICML 2026 · 1 citation
Builds on10
- CryptoGuard: High Precision Detection of Cryptographic Vulnerabilities in Massive-sized Java ProjectsSazzadur Rahaman, Ya Xiao, Sharmin Afrose, Fahad Shaon et al.CCS 2019 · 159 citations
- A Stitch in Time: Supporting Android Developers in WritingSecure CodeDuc Cuong Nguyen, Dominik Wermke, Yasemin Acar, Michael Backes et al.CCS 2017 · 125 citations
- "They're not that hard to mitigate": What Cryptographic Library Developers Think About Timing AttacksJan Jancar, Marcel Fourné, Daniel De Almeida Braga, Mohamed Sabt et al.S&P 2022 · 61 citations
- How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview StudyMarco Gutfleisch, Jan H. Klemmer, Niklas Busch, Yasemin Acar et al.S&P 2022 · 51 citations
- Listen to Developers! A Participatory Design Study on Security Warnings for Cryptographic APIsPeter Leo Gorski, Yasemin Acar, Luigi Lo Iacono, Sascha FahlCHI 2020 · 39 citations
Related papers
- Practitioners' Expectations on Automated Test GenerationXiao Yu, Lei Liu, Xing Hu, Jacky Keung et al.ISSTA 2024 · 5 citations
- IDE support for cloud-based static analysesLinghui Luo, Martin Schäf, Daniel Sanchez, Eric BoddenFSE 2021 · 8 citations
- An Empirical Study of Static Analysis Tools for Secure Code ReviewWachiraphan Charoenwet, Patanamon Thongtanunam, Van-Thuan Pham, Christoph TreudeISSTA 2024 · 19 citations
- A Qualitative Study of Dependency Management and Its Security ImplicationsIvan Pashchenko, Duc-Ly Vu, Fabio MassacciCCS 2020 · 84 citations
- One size does not fit all: a grounded theory and online survey study of developer preferences for security warning typesAnastasia Danilova, Alena Naiakshina, Matthew SmithICSE 2020 · 24 citations
