首页> 外文会议>IEEE/ACM International Workshop on Cooperative and Human Aspects of Software Engineering >'Hopefully We Are Mostly Secure': Views on Secure Code in Professional Practice
【24h】

'Hopefully We Are Mostly Secure': Views on Secure Code in Professional Practice

机译:“希望我们最安全”:专业实践中对安全代码的看法

获取原文
获取外文期刊封面目录资料

摘要

Security of software systems is of general concern, yet breaches caused by common vulnerabilities still occur. Software developers are routinely called upon to 'do more' to address this situation. However there has been little focus on the developers' point of view, and understanding how security features in their day-to-day activities. This paper reports preliminary findings of semi-structured interviews taken during an ethnographic study of professional software developers in one organization who are not security experts. The overall study aims to understand how security features in day-to-day practice, while analysis of the interview data asks whether developers are responsible for security. The study reveals that awareness around security matters is raised through several paths including processes, standards, practices and company training and that a focus on security is driven by contextual factors. Security is taken care of with policies and through safeguards, and is handled differently depending on whether a team is developing new features, and hence 'looking forward', or working with existing code and hence 'looking back'. Developers take and share responsibility for security in the code, but suggest that their responsibility has limits, and relies on collective practice.
机译:软件系统的安全性是普遍关注的问题,但是仍然存在由常见漏洞引起的破坏。通常要求软件开发人员“做更多的事情”以解决这种情况。但是,很少有人关注开发人员的观点,以及他们在日常活动中如何了解安全性。本文报告了对一个组织中的非安全专家的专业软件开发人员进行的人种志研究期间进行的半结构化访谈的初步发现。总体研究旨在了解安全性在日常实践中的作用,而对访谈数据的分析则询问开发人员是否应对安全性负责。该研究表明,人们对安全问题的认识是通过多种途径来提高的,包括流程,标准,实践和公司培训,并且对安全性的关注是由上下文因素驱动的。安全是通过策略和安全措施来处理的,并且根据团队是开发新功能(因此是“向前看”)还是使用现有代码并因此“回头”来对安全进行不同的处理。开发人员在代码中承担并分担了代码安全性的责任,但建议他们的责任是有限的,并且要依靠集体实践。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号