首页> 外文会议>International symposium on engineering secure software and systems >An Empirical Study on the Effectiveness of Security Code Review
【24h】

An Empirical Study on the Effectiveness of Security Code Review

机译:证券法规审查有效性的实证研究

获取原文

摘要

With the rise of the web as a dominant application platform, web security vulnerabilities are of increasing concern. Ideally, the web application development process would detect and correct these vulnerabilities before they are released to the public. This research aims to quantify the effectiveness of software developers at security code review as well as determine the variation in effectiveness among web developers. We hired 30 developers to conduct a manual code review of a small web application. The web application supplied to developers had seven known vulnerabilities, including three different types: Cross-Site Scripting, Cross-Site Request Forgery, and SQL Injection. Our findings include: (1) none of the subjects found all confirmed vulnerabilities, (2) more experience does not necessarily mean that the reviewer will be more accurate or effective, and (3) reports of false vulnerabilities were significantly correlated with reports of valid vulnerabilities.
机译:随着Web作为主要应用程序平台的兴起,Web安全漏洞越来越受到关注。理想情况下,Web应用程序开发过程会在将这些漏洞发布给公众之前检测并纠正这些漏洞。这项研究旨在量化软件开发人员在安全代码审查中的有效性,并确定Web开发人员之间有效性的差异。我们雇用了30个开发人员来对小型Web应用程序进行手动代码审查。提供给开发人员的Web应用程序具有七个已知漏洞,包括三种不同类型:跨站点脚本,跨站点请求伪造和SQL注入。我们的发现包括:(1)没有一个主题发现所有已确认的漏洞;(2)更多的经验并不一定意味着审阅者将更加准确或有效;(3)虚假漏洞的报告与有效漏洞的报告显着相关。漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号