首页> 外文OA文献 >How to Improve the Security Skills of Mobile App Developers:An Analysis of Expert Knowledge
【2h】

How to Improve the Security Skills of Mobile App Developers:An Analysis of Expert Knowledge

机译:如何提高移动应用程序开发人员的安全技能:专家知识分析

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Much of the world relies heavily on apps. Increasingly those apps handle sensitive information: controlling our financial transactions, enabling our personal communication and holding intimate details of our lives. So the security of those apps is becoming increasingly vital. Yet research shows that those apps contain frequent security and privacy problems; and that almost all of these issues could have been avoided had the developers had sufficient motivation, support and knowledge. This lack of developer knowledge and support is widely perceived as a major threat. We therefore investigated the skills, approach and motivation required for developers. We conducted a Constructivist Grounded Theory study, involving face-to-face interviews with a dozen experts whose cumulative experience totalled over 100 years of secure app development, to develop theory on secure development techniques. The study identified that the subdiscipline of app development security is still at an early stage, and found surprising discrepancies between current industry understanding and the experts’ recommendations. In particular it found that a secure development process tends not to appeal to app developers; and that the approach of identifying common types of security problems is too limited to give an effective security solution. Instead we identified a set of successful techniques we call ‘Dialectical Security’, where ‘dialectic’ means learning by questioning. These techniques use dialogue with a range of counterparties to achieve app security in an effective and economical way. The security increase comes from continued dialog, not passive learning. The novel contribution of our work is to provide:  A grounded theory of secure app development that challenges conventional processes and checklists, and  A shift in perspective from process to dialectic. Only by working to develop the Dialectical Security skills of app developers shall we begin to see the kinds of secure apps we need to combat crime and privacy invasions.
机译:世界上很多地方都严重依赖应用程序。这些应用程序越来越多地处理敏感信息:控制我们的财务交易,实现我们的个人通信并保存我们生活的亲密细节。因此,这些应用程序的安全性变得越来越重要。然而研究表明,这些应用经常包含安全性和隐私问题。如果开发人员有足够的动力,支持和知识,几乎所有这些问题都可以避免。缺乏开发人员的知识和支持被普遍认为是主要威胁。因此,我们调查了开发人员所需的技能,方法和动机。我们进行了建构主义扎根理论研究,包括与十几位专家的面对面访谈,这些专家累计积累了超过100年的安全应用程序开发经验,以开发有关安全开发技术的理论。研究发现,应用程序开发安全性的子学科仍处于早期阶段,并发现当前的行业理解与专家的建议之间存在令人惊讶的差异。特别是,它发现安全的开发过程往往不会吸引应用程序开发人员。并且识别常见类型的安全问题的方法过于局限,无法提供有效的安全解决方案。取而代之的是,我们确定了一套成功的技术,称为“方言安全”,“方言”是指通过提问进行学习。这些技术使用与众多交易对手的对话,以有效且经济的方式实现应用程序安全。安全性的提高来自持续的对话,而不是被动学习。我们工作的新颖贡献在于:建立安全的应用程序开发基础理论,挑战传统流程和清单,以及从流程到辩证法的转变。只有致力于开发应用程序开发人员的“辩证安全性”技能,我们才能开始看到应对犯罪和隐私入侵所需的各种安全应用程序。

著录项

  • 作者

    Weir Charles;

  • 作者单位
  • 年度 2017
  • 总页数
  • 原文格式 PDF
  • 正文语种
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号