首页> 外文会议>IEEE/ACM International Conference on Software Engineering: Joint Track on Software Engineering Education and Training >Is Secure Coding Education in the Industry Needed? An Investigation Through a Large Scale Survey
【24h】

Is Secure Coding Education in the Industry Needed? An Investigation Through a Large Scale Survey

机译:在行业中是安全的编码教育需要吗? 通过大规模调查调查

获取原文

摘要

The Department of Homeland Security in the United States estimates that 90% of software vulnerabilities can be traced back to defects in design and software coding. The financial impact of these vulnerabilities has been shown to exceed 380 million USD in industrial control systems alone. Since software developers write software, they also introduce these vulnerabilities into the source code. However, secure coding guidelines exist to prevent software developers from writing vulnerable code. This study focuses on the human factor, the software developer, and secure coding, in particular secure coding guidelines. We want to understand the software developers’ awareness and compliance to secure coding guidelines and why, if at all, they aren’t compliant or aware. We base our results on a large-scale survey on secure coding guidelines, with more than 190 industrial software developers. Our work’s main contribution motivates the need to educate industrial software developers on secure coding guidelines, and it gives a list of fifteen actionable items to be used by practitioners in the industry. We also make our raw data openly available for further research.
机译:美国国土安全部估计,90%的软件漏洞可以追溯到设计和软件编码中的缺陷。仅显示了这些漏洞的财务影响,仅在工业控制体系中超过380万美元。由于软件开发人员编写软件,他们还将这些漏洞介绍到源代码中。但是,存在安全编码指南,以防止软件开发人员写入易受攻击的代码。本研究侧重于人为因素,软件开发人员和安全编码,特别是安全编码指南。我们希望了解软件开发人员的意识和遵守,以确保编码指南,以及为什么,如果有的话,他们不符合或意识到。我们将结果基于关于安全编码指南的大规模调查,超过190个工业软件开发人员。我们的工作主要贡献促使有必要教育工业软件开发人员在安全的编码指南上,并列出了该行业中的从业者使用的十五个可行项目。我们还将我们的原始数据公开可用于进一步研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号