Leveraging Practitioners' Feedback to Improve a Security Linter
Sofia Reis, Rui Abreu, Marcelo d'Amorim, Daniel Fortunato
Abstract
Infrastructure-as-Code (IaC) is a technology that enables the management and distribution of infrastructure through code instead of manual processes. In 2020, Palo Alto Network's Unit 42 announced the discovery of over 199K vulnerable IaC templates through their "Cloud Threat" Report. This report highlights the importance of tools to prevent vulnerabilities from reaching production. Unfortunately, we observed through a comprehensive study that a security linter for IaC scripts is not reliable yet-high false positive rates. Our approach to tackling this problem was to leverage community expertise to improve the precision of this tool. More precisely, we interviewed professional developers to collect their feedback on the root causes of imprecision of the state-of-the-art security linter for Puppet. From that feedback, we developed a linter adjusting 7 rules of an existing linter ruleset and adding 3 new rules. We conducted a new study with 131 practitioners, which helped us improve the tool's precision significantly and achieve a final precision of 83%. An important takeaway from this paper is that obtaining professional feedback is fundamental to improving the rules' precision and extending the rulesets, which is critical for the usefulness and adoption of lightweight tools, such as IaC security linters. CCS CONCEPTS • Security and privacy → Vulnerability scanners.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext eccbab95-d172-456c-a952-3bae1fe57188Cited by top-tier papers1
Ask how each one uses itBuilds on1
Related papers
- GLITCH: Automated Polyglot Security Smell Detection in Infrastructure as CodeNuno Saavedra, João F. FerreiraASE 2022 · 27 citations
- Deployability-Centric Infrastructure-as-Code Generation: Fail, Learn, Refine, and Succeed through LLM-Empowered DevOps SimulationTianyi Zhang, Shidong Pan, Zejun Zhang, Zhenchang Xing et al.FSE 2026 · 1 citation
- When Your Infrastructure Is a Buggy Program: Understanding Faults in Infrastructure as Code EcosystemsGeorgios-Petros Drosos, Thodoris Sotiropoulos, Georgios Alexopoulos, Dimitris Mitropoulos et al.OOPSLA 2024 · 14 citations
- Gang of eight: a defect taxonomy for infrastructure as code scriptsAkond Rahman, Effat Farhana, Chris Parnin, Laurie A. WilliamsICSE 2020 · 58 citations
- Closing the Gap: A User Study on the Real-world Usefulness of AI-powered Vulnerability Detection & Repair in the IDEBenjamin Steenhoek, Kalpathy Sivaraman, Renata Saldivar Gonzalez, Yevhen Mohylevskyy et al.ICSE 2025 · 3 citations
