kirancodes.me
To Proof Maintenance & Beyond!

Questions developers ask while diagnosing potential security vulnerabilities with static analysis

Justin Smith, Brittany Johnson, Emerson R. Murphy-Hill, Bill Chu, Heather Richter Lipford

Abstract

Security tools can help developers answer questions about potential vulnerabilities in their code. A better understanding of the types of questions asked by developers may help toolsmiths design more effective tools. In this paper, we describe how we collected and categorized these questions by conducting an exploratory study with novice and experienced software developers. We equipped them with Find Security Bugs, a security-oriented static analysis tool, and observed their interactions with security vulnerabilities in an open-source system that they had previously contributed to. We found that they asked questions not only about security vulnerabilities, associated attacks, and fixes, but also questions about the software itself, the social ecosystem that built the software, and related resources and tools. For example, when participants asked questions about the source of tainted data, their tools forced them to make imperfect tradeoffs between systematic and ad hoc program navigation strategies.

BibTeX
@inproceedings{Smith-al:FSE15,
  author    = {Justin Smith and
               Brittany Johnson and
               Emerson R. Murphy{-}Hill and
               Bill Chu and
               Heather Richter Lipford},
  title     = {Questions developers ask while diagnosing potential security vulnerabilities with static analysis},
  booktitle = {{ESEC/SIGSOFT} {FSE}},
  pages     = {248--259},
  publisher = {{ACM}},
  year      = {2015},
}

Related papers