Less is More: Supporting Developers in Vulnerability Detection during Code Review
Abstract
Reviewing source code from a security perspective has proven to be a difficult task. Indeed, previous research has shown that developers often miss even popular and easy-to-detect vulnerabilities during code review. Initial evidence suggests that a significant cause may lie in the reviewers' mental attitude and common practices.
BibTeX
@inproceedings{Braz-al:ICSE22,
author = {Larissa Braz and
Christian Aeberhard and
G{\"{u}}l {\c{C}}alikli and
Alberto Bacchelli},
title = {Less is More: Supporting Developers in Vulnerability Detection during Code Review},
booktitle = {ICSE},
pages = {1317--1329},
publisher = {{ACM}},
year = {2022},
}