Interpretable Vulnerability Detection Reports
Cláudia Mamede, José Campos, Claire Le Goues, Rui Abreu
Abstract
Software security faces a persistent gap: static analysis tools detect vulnerabilities effectively, but their technical outputs remain inaccessible to most developers. This leads to mounting security debt, as organizations must rely on security specialists for remediation, creating bottlenecks that delay fixes. This paper proposes an interpretability convention and a modular workflow that transforms raw static analyzer outputs into clear, actionable vulnerability reports for all developers, not just security experts. Our tool, SECGen, automates the workflow by parsing static analyzer outputs and restructuring them into clear, developer-friendly reports based on our convention, and enforcing compliance through automated validation. We validated our approach through a user study with 25 developers, comparing our interpretable reports to other state-of-the-art static analyzer outputs. The results suggest that developers using interpretable reports detect, understand and fix vulnerabilities more effectively, requiring only 67% of the time typically spent with traditional reports while writing more correct fixes. Key reasons for this include participants’ preference for structured reports, with clear vulnerability descriptions and actionable fix suggestions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e1976ccd-4f7f-4d85-a91c-efec98a8199aBuilds on11
- Using an LLM to Help With Code UnderstandingDaye Nam, Andrew Macvean, Vincent J. Hellendoorn, Bogdan Vasilescu et al.ICSE 2024 · 264 citations
- Enhancing Static Analysis for Practical Bug Detection: An LLM-Integrated ApproachHaonan Li, Yu Hao, Yizhuo Zhai, Zhiyun QianOOPSLA 2024 · 142 citations
- An empirical study on the effectiveness of static C code analyzers for vulnerability detectionStephan Lipp, Sebastian Banescu, Alexander PretschnerISSTA 2022 · 99 citations
- Listen to Developers! A Participatory Design Study on Security Warnings for Cryptographic APIsPeter Leo Gorski, Yasemin Acar, Luigi Lo Iacono, Sascha FahlCHI 2020 · 39 citations
- A large-scale study of usability criteria addressed by static analysis toolsMarcus Nachtigall, Michael Schlichtig, Eric BoddenISSTA 2022 · 38 citations
Related papers
- "False negative - that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security TestingAmit Seal Ami, Kevin Moran, Denys Poshyvanyk, Adwait NadkarniS&P 2024 · 40 citations
- Learning to Reduce False Positives in Analytic Bug DetectorsAnant Kharkar, Roshanak Zilouchian Moghaddam, Matthew Jin, Xiaoyu Liu et al.ICSE 2022 · 33 citations
- IDE support for cloud-based static analysesLinghui Luo, Martin Schäf, Daniel Sanchez, Eric BoddenFSE 2021 · 8 citations
- Improving Logging to Reduce Permission Over-Granting MistakesBingyu Shen, Tianyi Shan, Yuanyuan ZhouUSENIX Security 2023
- Security Notifications in Static Analysis Tools: Developers' Attitudes, Comprehension, and Ability to Act on ThemMohammad Tahaei, Kami Vaniea, Konstantin Beznosov, Maria K. WoltersCHI 2021 · 35 citations
