EASE 2023
Tue 13 - Fri 16 June 2023 Oulu, Finland
Wed 14 Jun 2023 13:50 - 14:00 at Aurora Hall - Repository Mining Chair(s): César França

The fast distribution and deployment of security patches is important to protect users against cyberattacks. These fixes can be detected automatically by patch management triage systems. However, previous work has shown that automating the task is not easy, in some cases, because of poor documentation or lack of information in security fixes. For many years, standard practices in the security community have steered engineers to provide cryptic commit messages—i.e., patch software vulnerabilities silently—to avoid potential attacks and reputation damages. However, not providing enough documentation on vulnerability fixes is known to damage trust between vendors and users. Current efforts in the security community aim to increase the level of transparency during patch and disclosing times to help build trust in the development community and make patch management processes faster. In this paper, we evaluate how informative security commit messages (i.e., messages attached to security fixes) are and how different levels of information can affect the different tasks in automated patch triage systems. We observed that security engineers provide some levels of detail in security commit messages that can be leveraged to improve or enable one or two of the automated triage tasks but not all of them. In addition, results show that security commit messages need to be more informative—56.6% of the messages analyzed were documented poorly. Best practices to write informative and well-structured security commit messages (such as SECOM) should become a standard practice in the security community.

Wed 14 Jun

Displayed time zone: Athens change

13:30 - 15:00
Repository MiningIndustry / Short Papers and Posters / Research (Full Papers) at Aurora Hall
Chair(s): César França Universidade Federal Rural de Pernambuco
13:30
20m
Paper
An Empirical Study on Continuous Integration Trends, Topics and Challenges in Stack Overflow
Research (Full Papers)
Ali Ouni ETS Montreal, University of Quebec, Islem Saidani ETS, Eman Abdullah AlOmar Stevens Institute of Technology, Mohamed Wiem Mkaouer Rochester Institute of Technology
Link to publication DOI Media Attached File Attached
13:50
10m
Paper
Are security commit messages informative? Not enough!Industry Experience Report
Industry
Sofia Reis Instituto Superior Técnico, U. Lisboa & INESC-ID, Rui Abreu Faculty of Engineering, University of Porto, Corina S. Pasareanu Carnegie Mellon University Silicon Valley, NASA Ames Research Center
Link to publication DOI
14:00
20m
Paper
Analyzing the Resource Usage Overhead of Mobile App Development Frameworks
Research (Full Papers)
Wellington de Oliveira Júnior University of Lisbon, Bernardo de Moraes Santana Júnior , Fernando Castor Utrecht University & Federal University of Pernambuco, João Paulo Fernandes LIACC, Universidade do Porto, Porto, Portugal
Link to publication Pre-print File Attached
14:20
10m
Short-paper
Analysis of Bug Report Qualities with Fixing Time using a Bayesian NetworkShort Paper
Short Papers and Posters
Sien Reeve O. Peralta Waseda University, Hironori Washizaki Waseda University, Yoshiaki Fukazawa Waseda University, Yuki Noyori Hitachi, Ltd., Shuhei Nojiri Hitachi, Ltd., Yokohama Reserch Laboratory, Hideyuki Kanuka Hitachi, Ltd.
DOI File Attached
14:30
10m
Short-paper
Outside the Sandbox: A Study of Input/Output Methods in JavaShort Paper
Short Papers and Posters
Matúš Sulír Technical University of Košice, Sergej Chodarev Technical University of Košice, Milan Nosáľ ValeSoft, s.r.o.
DOI Pre-print File Attached
14:40
10m
Paper
NxtUnit: Automated Unit Test Generation for GoIndustry Experience Report
Industry
Siwei Wang bytedance, Xue Mao bytedance, Ziguang Cao bytedance, Yujun Gao bytedance, Qucheng Shen bytedance, Chao Peng ByteDance, China
DOI Pre-print Media Attached
14:50
10m
Short-paper
Identifying Characteristics of the Agile Development Process That Impact User SatisfactionShort Paper
Short Papers and Posters
Minshun Yang Department of Computer Science and Communications Engineering, Waseda University, Seiji Sato Department of Computer Science and Communications Engineering, Waseda University, Hironori Washizaki Waseda University, Yoshiaki Fukazawa Waseda University, Juichi Takahashi AGEST, Inc
DOI Pre-print File Attached