Measuring Secure Coding Practice and Culture: A Finger Pointing at the Moon is not the Moon
Ita Ryan, Utz Roedig, Klaas-Jan Stol
摘要
Software security research has a core problem: it is impossible to prove the security of complex software. A low number of known defects may simply indicate that the software has not been attacked yet, or that successful attacks have not been detected. A high defect count may be the result of white-hat hacker targeting, or of a successful bug bounty program which prevented insecurities from persisting in the wild. This makes it difficult to measure the security of non-trivial software. Researchers instead usually measure effort directed towards ensuring software security. However, different researchers use their own tailored measures, usually devised from industry secure coding guidelines. Not only is there no agreed way to measure effort, there is also no agreement on what effort entails. Qualitative studies emphasise the importance of security culture in an organisation. Where software security practices are introduced solely to ensure compliance with legislative or industry standards, a box-ticking attitude to security may result. The security culture may be weak or non-existent, making it likely that precautions not explicitly mentioned in the standards will be missed. Thus, researchers need both a way to assess software security practice and a way to measure software security culture. To assess security practice, we converted the empirically-established 12 most common software security activities into questions. To assess security culture, we devised a number of questions grounded in prior literature. We ran a secure development survey with both sets of questions, obtaining organic responses from 1,100 software coders in 59 countries. We used proven common activities to assess security practice, and made a first attempt to quantitatively assess aspects of security culture in the broad developer population. Our results show that some coders still work in environments where there is little to no attempt to ensure code security. Security practice and culture do not always correlate, and some organisations with strong secure coding practice have weak secure coding culture. This may lead to problems in defect prevention and sustained software security effort.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Unhelpful Assumptions in Software Security ResearchIta Ryan, Utz Roedig, Klaas-Jan StolCCS 2023 · 被引用 9 次
- Mapping the Cloud: A Mixed-Methods Study of Cloud Security and Privacy Configuration ChallengesSumair Ijaz Hashmi, Shafay Kashif, Lea Gröber, Katharina Krombholz 等NDSS 2026 · 被引用 3 次
- Weak Programmers Need Not Apply, LLMs Welcome! Survey Screening in the AI EraIta Ryan, Utz Roedig, Klaas-Jan StolICSE 2026
它引用的顶会 Paper9
- Why Do Developers Get Password Storage Wrong?: A Qualitative Usability StudyAlena Naiakshina, Anastasia Danilova, Christian Tiefenau, Marco Herzog 等CCS 2017 · 被引用 146 次
- A Qualitative Study of Dependency Management and Its Security ImplicationsIvan Pashchenko, Duc-Ly Vu, Fabio MassacciCCS 2020 · 被引用 84 次
- Privacy Champions in Software Teams: Understanding Their Motivations, Strategies, and ChallengesMohammad Tahaei, Alisa Frik, Kami VanieaCHI 2021 · 被引用 75 次
- On Conducting Security Developer Studies with CS Students: Examining a Password-Storage Study with CS Students, Freelancers, and Company DevelopersAlena Naiakshina, Anastasia Danilova, Eva Gerlitz, Matthew SmithCHI 2020 · 被引用 48 次
- Building and Validating a Scale for Secure Software Development Self-EfficacyDaniel Votipka, Desiree Abrokwa, Michelle L. MazurekCHI 2020 · 被引用 35 次
相关 Paper
- Software security during modern code review: the developer's perspectiveLarissa Braz, Alberto BacchelliFSE 2022 · 被引用 28 次
- Analyzing the Use of Public and In-house Secure Development Guidelines in U.S. and Japanese IndustriesFumihiro Kanei, Ayako Akiyama Hasegawa, Eitaro Shioji, Mitsuaki AkiyamaCHI 2023 · 被引用 4 次
- An Empirical Study on Software Bill of Materials: Where We Stand and the Road AheadBoming Xia, Tingting Bi, Zhenchang Xing, Qinghua Lu 等ICSE 2023 · 被引用 82 次
- Less is More: Supporting Developers in Vulnerability Detection during Code ReviewLarissa Braz, Christian Aeberhard, Gül Çalikli, Alberto BacchelliICSE 2022 · 被引用 26 次
- An Industry Interview Study of Software Signing for Supply Chain SecurityKelechi G. Kalu, Tanmay Singla, Chinenye Okafor, Santiago Torres-Arias 等USENIX Security 2025
