"Think secure from the beginning": A Survey with Software Developers

被引:64
|
作者
Assal, Hala [1 ]
Chiasson, Sonia [1 ]
机构
[1] Carleton Univ, Sch Comp Sci, Ottawa, ON, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
Security; Survey; HCI for development; Secure programming; STATIC ANALYSIS;
D O I
10.1145/3290605.3300519
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Vulnerabilities persist despite existing software security initiatives and best practices. This paper focuses on the human factors of software security, including human behaviour and motivation. We conducted an online survey to explore the interplay between developers and software security processes, e.g., we looked into how developers influence and are influenced by these processes. Our data included responses from 123 software developers currently employed in North America who work on various types of software applications. Whereas developers are often held responsible for security vulnerabilities, our analysis shows that the real issues frequently stem from a lack of organizational or process support to handle security throughout development tasks. Our participants are self-motivated towards software security, and the majority did not dismiss it but identified obstacles to achieving secure code. Our work highlights the need to look beyond the individual, and take a holistic approach to investigate organizational issues influencing software security.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] Nudging Software Developers Toward Secure Code
    Fischer, Felix
    Grossklags, Jens
    [J]. IEEE SECURITY & PRIVACY, 2022, 20 (02) : 76 - 79
  • [2] A Survey on What Developers Think About Testing
    Straubinger, Philipp
    Fraser, Gordon
    [J]. 2023 IEEE 34TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING, ISSRE, 2023, : 80 - 90
  • [3] Raising Secure Coding Awareness for Software Developers in the Industry
    Gasiba, Tiago
    Lechner, Ulrike
    [J]. 2019 IEEE 27TH INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE WORKSHOPS (REW 2019), 2019, : 141 - 143
  • [4] Will you use software development support using biosignals? A survey from software developers
    Soga, Ryo
    Kanuka, Hideyuki
    Kubo, Takatomi
    Ishio, Takashi
    Matsumoto, Kenichi
    [J]. Proceedings of the International Conference on Software Engineering and Knowledge Engineering, SEKE, 2023, 2023-July : 31 - 36
  • [5] Developers Need Support, Too: A Survey of Security Advice for Software Developers
    Acar, Yasemin
    Stransky, Christian
    Wermke, Dominik
    Weir, Charles
    Mazurek, Michelle L.
    Fahl, Sascha
    [J]. 2017 IEEE CYBERSECURITY DEVELOPMENT (SECDEV), 2017, : 22 - 26
  • [6] Acceptable protection of software intellectual property: a survey of software developers and lawyers
    Oz, E
    [J]. INFORMATION & MANAGEMENT, 1998, 34 (03) : 161 - 173
  • [7] Improving speed and productivity of software development: A global survey of software developers
    Blackburn, JD
    Scudder, GD
    VanWassenhove, LN
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 1996, 22 (12) : 875 - 885
  • [8] Factors Affecting Secure Software Development Practices Among Developers - An Investigation
    Maher, Zulfikar Ahmed
    Shaikh, Humaiz
    Khan, Mohammad Shadab
    Arbaaeen, Ammar
    Shah, Asadullah
    [J]. 2018 5TH IEEE INTERNATIONAL CONFERENCE ON ENGINEERING TECHNOLOGIES AND APPLIED SCIENCES (IEEE ICETAS), 2018,
  • [9] ClockIt: Collecting Quantitative Data on How Beginning Software Developers Really Work
    Norris, Cindy
    Barry, Frank
    Fenwick, James B., Jr.
    Reid, Kathryn
    Rountree, Josh
    [J]. ITICSE '08: PROCEEDINGS OF THE 13TH ANNUAL CONFERENCE ON INNOVATION AND TECHNOLOGY IN COMPUTER SCIENCE EDUCATION, 2008, : 37 - 41
  • [10] Understanding the motivations, challenges and needs of Blockchain software developers: a survey
    Amiangshu Bosu
    Anindya Iqbal
    Rifat Shahriyar
    Partha Chakraborty
    [J]. Empirical Software Engineering, 2019, 24 : 2636 - 2673