Security Notifications in Static Analysis Tools: Developers' Attitudes, Comprehension, and Ability to Act on Them
Mohammad Tahaei, Kami Vaniea, Konstantin Beznosov, Maria K. Wolters
摘要
Static analysis tools (SATs) have the potential to assist developers in finding and fixing vulnerabilities in the early stages of software development, requiring them to be able to understand and act on tools' notifications. To understand how helpful such SAT guidance is to developers, we ran an online experiment (N=132) where participants were shown four vulnerable code samples (SQL injection, hard-coded credentials, encryption, and logging sensitive data) along with SAT guidance, and asked to indicate the appropriate fix. Participants had a positive attitude towards both SAT notifications and particularly liked the example solutions and vulnerable code. Seeing SAT notifications also led to more detailed open-ended answers and slightly improved code correction answers. Still, most SAT (SpotBugs 67%, SonarQube 86%) and Control (96%) participants answered at least one code-correction question incorrectly. Prior software development experience, perceived vulnerability severity, and answer confidence all positively impacted answer accuracy.
• Human-centered computing → Empirical studies in HCI;
• Security and privacy → Usability in security and privacy; Software and application security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper10
- Recruiting Participants With Programming Skills: A Comparison of Four Crowdsourcing Platforms and a CS Student Mailing ListMohammad Tahaei, Kami VanieaCHI 2022 · 被引用 45 次
- Detecting False Alarms from Automatic Static Analysis Tools: How Far are We?Hong Jin Kang, Khai Loong Aw, David LoICSE 2022 · 被引用 42 次
- Stuck in the Permissions With You: Developer & End-User Perspectives on App Permissions & Their Privacy RamificationsMohammad Tahaei, Ruba Abu-Salma, Awais RashidCHI 2023 · 被引用 36 次
- "I Don't Know If We're Doing Good. I Don't Know If We're Doing Bad": Investigating How Practitioners Scope, Motivate, and Conduct Privacy Work When Developing AI ProductsHao-Ping (Hank) Lee, Lan Gao, Stephanie S. Yang, Jodi Forlizzi 等USENIX Security 2024 · 被引用 14 次
- Understanding VR Accessibility Practices of VR ProfessionalsYi Wang, Xiao Liu, Chetan Arora, John Grundy 等CHI 2025 · 被引用 13 次
它引用的顶会 Paper14
- You Get Where You're Looking for: The Impact of Information Sources on Code SecurityYasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim 等S&P 2016 · 被引用 325 次
- Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application SecurityFelix Fischer, Konstantin Böttinger, Huang Xiao, Christian Stransky 等S&P 2017 · 被引用 293 次
- Comparing the Usability of Cryptographic APIsYasemin Acar, Michael Backes, Sascha Fahl, Simson L. Garfinkel 等S&P 2017 · 被引用 261 次
- Automated Analysis of Privacy Requirements for Mobile AppsSebastian Zimmeck, Ziqi Wang, Lieyong Zou, Roger Iyengar 等NDSS 2017 · 被引用 255 次
- CryptoGuard: High Precision Detection of Cryptographic Vulnerabilities in Massive-sized Java ProjectsSazzadur Rahaman, Ya Xiao, Sharmin Afrose, Fahad Shaon 等CCS 2019 · 被引用 159 次
相关 Paper
- A large-scale study of usability criteria addressed by static analysis toolsMarcus Nachtigall, Michael Schlichtig, Eric BoddenISSTA 2022 · 被引用 38 次
- IDE support for cloud-based static analysesLinghui Luo, Martin Schäf, Daniel Sanchez, Eric BoddenFSE 2021 · 被引用 8 次
- An Empirical Study of Static Analysis Tools for Secure Code ReviewWachiraphan Charoenwet, Patanamon Thongtanunam, Van-Thuan Pham, Christoph TreudeISSTA 2024 · 被引用 19 次
- "False negative - that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security TestingAmit Seal Ami, Kevin Moran, Denys Poshyvanyk, Adwait NadkarniS&P 2024 · 被引用 40 次
- One size does not fit all: a grounded theory and online survey study of developer preferences for security warning typesAnastasia Danilova, Alena Naiakshina, Matthew SmithICSE 2020 · 被引用 24 次
