kirancodes.me
To Proof Maintenance & Beyond!

Quantifying developers' adoption of security tools

Jim Witschey, Olga A. Zielinska, Allaire K. Welk, Emerson R. Murphy-Hill, Christopher B. Mayhorn, Thomas Zimmermann

Abstract

Security tools could help developers find critical vulnerabilities, yet such tools remain underused. We surveyed developers from 14 companies and 5 mailing lists about their reasons for using and not using security tools. The resulting thirty-nine predictors of security tool use provide both expected and unexpected insights. As we expected, developers who perceive security to be important are more likely to use security tools than those who do not. But that was not the strongest predictor of security tool use, it was instead developers' ability to observe their peers using security tools.

BibTeX
@inproceedings{Witschey-al:FSE15,
  author    = {Jim Witschey and
               Olga A. Zielinska and
               Allaire K. Welk and
               Emerson R. Murphy{-}Hill and
               Christopher B. Mayhorn and
               Thomas Zimmermann},
  title     = {Quantifying developers' adoption of security tools},
  booktitle = {{ESEC/SIGSOFT} {FSE}},
  pages     = {260--271},
  publisher = {{ACM}},
  year      = {2015},
}

Related papers