Software security during modern code review: the developer's perspective
Larissa Braz, Alberto Bacchelli
摘要
To avoid software vulnerabilities, organizations are shifting security to earlier stages of the software development, such as at code review time. In this paper, we aim to understand the developers’ perspective on assessing software security during code review, the challenges they encounter, and the support that companies and projects provide. To this end, we conduct a two-step investigation: we interview 10 professional developers and survey 182 practitioners about software security assessment during code review. The outcome is an overview of how developers perceive software security during code review and a set of identified challenges. Our study revealed that most developers do not immediately report to focus on security issues during code review. Only after being asked about software security, developers state to always consider it during review and acknowledge its importance. Most companies do not provide security training, yet expect developers to still ensure security during reviews. Accordingly, developers report the lack of training and security knowledge as the main challenges they face when checking for security issues. In addition, they have challenges with third-party libraries and to identify interactions between parts of code that could have security implications. Moreover, security may be disregarded during reviews due to developers’ assumptions about the security dynamic of the application they develop. Preprint: https://arxiv.org/abs/2208.04261 Data and materials: https://doi.org/10.5281/zenodo.6969369
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- An Empirical Study of Static Analysis Tools for Secure Code ReviewWachiraphan Charoenwet, Patanamon Thongtanunam, Van-Thuan Pham, Christoph TreudeISSTA 2024 · 被引用 19 次
- Understanding VR Accessibility Practices of VR ProfessionalsYi Wang, Xiao Liu, Chetan Arora, John Grundy 等CHI 2025 · 被引用 13 次
- The Ivory Tower Syndrome: Operators' Reflections on Academic BGP Security SolutionsAleeza Suhel Inamdar, Tobias Fiebig, Mannat KaurUSENIX Security 2026
- SeRe: A Security-Related Code Review Dataset Aligned with Real-World Review ActivitiesZixiao Zhao, Yanjie Jiang, Hui Liu, Kui Liu 等ICSE 2026
它引用的顶会 Paper3
- Less is More: Supporting Developers in Vulnerability Detection during Code ReviewLarissa Braz, Christian Aeberhard, Gül Çalikli, Alberto BacchelliICSE 2022 · 被引用 26 次
- Do you really code? Designing and Evaluating Screening Questions for Online Surveys with ProgrammersAnastasia Danilova, Alena Naiakshina, Stefan Horstmann, Matthew SmithICSE 2021 · 被引用 5 次
- Why Don't Developers Detect Improper Input Validation? '; DROP TABLE Papers; -Larissa Braz, Enrico Fregnan, Gül Çalikli, Alberto BacchelliICSE 2021 · 被引用 1 次
相关 Paper
- Measuring Secure Coding Practice and Culture: A Finger Pointing at the Moon is not the MoonIta Ryan, Utz Roedig, Klaas-Jan StolICSE 2023 · 被引用 13 次
- "False negative - that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security TestingAmit Seal Ami, Kevin Moran, Denys Poshyvanyk, Adwait NadkarniS&P 2024 · 被引用 40 次
- Unhelpful Assumptions in Software Security ResearchIta Ryan, Utz Roedig, Klaas-Jan StolCCS 2023 · 被引用 9 次
- Why Security Defects Go Unnoticed during Code Reviews? A Case-Control Study of the Chromium OS ProjectRajshakhar Paul, Asif Kamal Turzo, Amiangshu BosuICSE 2021 · 被引用 2 次
- Interpersonal Conflicts During Code Review: Developers' Experience and PracticesPavlína Wurzel Gonçalves, Gül Çalikli, Alberto BacchelliCSCW 2022 · 被引用 11 次
