Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application Security
Felix Fischer, Konstantin Böttinger, Huang Xiao, Christian Stransky, Yasemin Acar, Michael Backes, Sascha Fahl
摘要
Online programming discussion platforms such as Stack Overflow serve as a rich source of information for software developers. Available information include vibrant discussions and oftentimes ready-to-use code snippets. Previous research identified Stack Overflow as one of the most important information sources developers rely on. Anecdotes report that software developers copy and paste code snippets from those information sources for convenience reasons. Such behavior results in a constant flow of community-provided code snippets into production software. To date, the impact of this behaviour on code security is unknown. We answer this highly important question by quantifying the proliferation of security-related code snippets from Stack Overflow in Android applications available on Google Play. Access to the rich source of information available on Stack Overflow including ready-to-use code snippets provides huge benefits for software developers. However, when it comes to code security there are some caveats to bear in mind: Due to the complex nature of code security, it is very difficult to provide ready-to-use and secure solutions for every problem. Hence, integrating a security-related code snippet from Stack Overflow into production software requires caution and expertise. Unsurprisingly, we observed insecure code snippets being copied into Android applications millions of users install from Google Play every day. To quantitatively evaluate the extent of this observation, we scanned Stack Overflow for code snippets and evaluated their security score using a stochastic gradient descent classifier. In order to identify code reuse in Android applications, we applied state-of-the-art static analysis. Our results are alarming: 15.4% of the 1.3 million Android applications we analyzed, contained security-related code snippets from Stack Overflow. Out of these 97.9% contain at least one insecure code snippet.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper44
- Do Users Write More Insecure Code with AI Assistants?Neil Perry, Megha Srivastava, Deepak Kumar, Dan BonehCCS 2023 · 被引用 150 次
- A Stitch in Time: Supporting Android Developers in WritingSecure CodeDuc Cuong Nguyen, Dominik Wermke, Yasemin Acar, Michael Backes 等CCS 2017 · 被引用 125 次
- Understanding Privacy-Related Questions on Stack OverflowMohammad Tahaei, Kami Vaniea, Naomi SaphraCHI 2020 · 被引用 93 次
- CRYLOGGER: Detecting Crypto Misuses DynamicallyLuca Piccolboni, Giuseppe Di Guglielmo, Luca P. Carloni, Simha SethumadhavanS&P 2021 · 被引用 51 次
- Why Eve and Mallory Still Love Android: Revisiting TLS (In)Security in Android ApplicationsMarten Oltrogge, Nicolas Huaman, Sabrina Amft, Yasemin Acar 等USENIX Security 2021 · 被引用 45 次
它引用的顶会 Paper1
相关 Paper
- Measuring the Effects of Stack Overflow Code Snippet Evolution on Open-Source Software SecurityAlfusainey Jallow, Michael Schilling, Michael Backes, Sven BugielS&P 2024 · 被引用 6 次
- The Effect of Google Search on Software Security: Unobtrusive Security Interventions via Content Re-rankingFelix Fischer, Yannick Stachelscheid, Jens GrossklagsCCS 2021 · 被引用 12 次
- Stack Overflow Considered Helpful! Deep Learning Security Nudges Towards Stronger CryptographyFelix Fischer, Huang Xiao, Ching-yu Kao, Yannick Stachelscheid 等USENIX Security 2019 · 被引用 44 次
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar 等CCS 2017 · 被引用 196 次
- Security code smells in apps: are we getting better?Steven ArztFSE 2022 · 被引用 3 次
