"False negative -- that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security Testing

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Ami, Amit Seal, Moran, Kevin, Poshyvanyk, Denys, Nadkarni, Adwait
Format: Preprint
Publié: 2023
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866913397195407360
author Ami, Amit Seal
Moran, Kevin
Poshyvanyk, Denys
Nadkarni, Adwait
author_facet Ami, Amit Seal
Moran, Kevin
Poshyvanyk, Denys
Nadkarni, Adwait
contents The demand for automated security analysis techniques, such as static analysis based security testing (SAST) tools continues to increase. To develop SASTs that are effectively leveraged by developers for finding vulnerabilities, researchers and tool designers must understand how developers perceive, select, and use SASTs, what they expect from the tools, whether they know of the limitations of the tools, and how they address those limitations. This paper describes a qualitative study that explores the assumptions, expectations, beliefs, and challenges experienced by developers who use SASTs. We perform in-depth, semi-structured interviews with 20 practitioners who possess a diverse range of software development expertise, as well as a variety of unique security, product, and organizational backgrounds. We identify $17$ key findings that shed light on developer perceptions and desires related to SASTs, and also expose gaps in the status quo - challenging long-held beliefs in SAST design priorities. Finally, we provide concrete future directions for researchers and practitioners rooted in an analysis of our findings.
format Preprint
id arxiv_https___arxiv_org_abs_2307_16325
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle "False negative -- that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security Testing
Ami, Amit Seal
Moran, Kevin
Poshyvanyk, Denys
Nadkarni, Adwait
Cryptography and Security
Software Engineering
The demand for automated security analysis techniques, such as static analysis based security testing (SAST) tools continues to increase. To develop SASTs that are effectively leveraged by developers for finding vulnerabilities, researchers and tool designers must understand how developers perceive, select, and use SASTs, what they expect from the tools, whether they know of the limitations of the tools, and how they address those limitations. This paper describes a qualitative study that explores the assumptions, expectations, beliefs, and challenges experienced by developers who use SASTs. We perform in-depth, semi-structured interviews with 20 practitioners who possess a diverse range of software development expertise, as well as a variety of unique security, product, and organizational backgrounds. We identify $17$ key findings that shed light on developer perceptions and desires related to SASTs, and also expose gaps in the status quo - challenging long-held beliefs in SAST design priorities. Finally, we provide concrete future directions for researchers and practitioners rooted in an analysis of our findings.
title "False negative -- that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security Testing
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2307.16325