首页> 外文会议>International Symposium on Engineering Secure Software and Systems >An Empirical Study on the Effectiveness of Security Code Review
【24h】

An Empirical Study on the Effectiveness of Security Code Review

机译:安全码审查有效性的实证研究

获取原文

摘要

With the rise of the web as a dominant application platform, web security vulnerabilities are of increasing concern. Ideally, the web application development process would detect and correct these vulnerabilities before they are released to the public. This research aims to quantify the effectiveness of software developers at security code review as well as determine the variation in effectiveness among web developers. We hired 30 developers to conduct a manual code review of a small web application. The web application supplied to developers had seven known vulnerabilities, including three different types: Cross-Site Scripting, Cross-Site Request Forgery, and SQL Injection. Our findings include: (1) none of the subjects found all confirmed vulnerabilities, (2) more experience does not necessarily mean that the reviewer will be more accurate or effective, and (3) reports of false vulnerabilities were significantly correlated with reports of valid vulnerabilities.
机译:随着Web的崛起作为主导应用程序平台,Web安全漏洞越来越高。理想情况下,Web应用程序开发过程将在向公众发布之前检测和纠正这些漏洞。本研究旨在量化软件开发人员在安全码审查中的有效性,并确定Web开发人员之间有效性的变化。我们聘请了30名开发人员对小型Web应用程序进行手动代码审查。向开发人员提供的Web应用程序有七种已知的漏洞,包括三种不同类型:跨站点脚本,跨站点请求伪造和SQL注入。我们的调查结果包括:(1)这些主题都没有发现所有确认的漏洞,(2)更多的经验并不一定意味着审阅者将更加准确或有效,并且(3)错误漏洞的报告与有效的报告显着相关漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号