Information on Potential Vulnerabilities for New Requirements: Does It Help Writing Secure Code?RE@Next
Recent research advocates a proactive approach toward addressing software vulnerability, i.e., identification and resolution of vulnerability before exploitation. To that end, a recent research has presented a framework to provide developers with information related to vulnerabilities that are identified with the existing implementation of functionally similar requirements. The idea is that a developer implementing a new requirement may learn from such vulnerability information and write her code in a secure manner. Given the various technologies and platforms a developer may use to implement the current system, to what extent such information would actually help in writing secure code is an open question. In this paper, we design a human subject study to explore how information related to potential vulnerabilities influence developers on secure implementation of new requirements. We further present a pilot run of our study with 50 participants. The results suggest that developers with limited professional experience could be a major beneficiary of the information on potential vulnerabilities.
Fri 24 SepDisplayed time zone: Eastern Time (US & Canada) change
12:00 - 12:20 | VulnerabilitiesRE@Next! Papers at Hesburgh Library Chair(s): Mona Rahimi Northern Illinois University | ||
12:00 20mTalk | Information on Potential Vulnerabilities for New Requirements: Does It Help Writing Secure Code?RE@Next RE@Next! Papers |