Quantifying developers' adoption of security tools
Abstract
Security tools could help developers find critical vulnerabilities, yet such tools remain underused. We surveyed developers from 14 companies and 5 mailing lists about their reasons for using and not using security tools. The resulting thirty-nine predictors of security tool use provide both expected and unexpected insights. As we expected, developers who perceive security to be important are more likely to use security tools than those who do not. But that was not the strongest predictor of security tool use, it was instead developers' ability to observe their peers using security tools.
BibTeX
@inproceedings{Witschey-al:FSE15,
author = {Jim Witschey and
Olga A. Zielinska and
Allaire K. Welk and
Emerson R. Murphy{-}Hill and
Christopher B. Mayhorn and
Thomas Zimmermann},
title = {Quantifying developers' adoption of security tools},
booktitle = {{ESEC/SIGSOFT} {FSE}},
pages = {260--271},
publisher = {{ACM}},
year = {2015},
}