A Survey of Web Application Security Tutorials

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Chembakottu, Bhagya, Robillard, Martin P.
Formato: Preprint
Publicado: 2026
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866911537640243200
author Chembakottu, Bhagya
Robillard, Martin P.
author_facet Chembakottu, Bhagya
Robillard, Martin P.
contents Developers rely on online tutorials to learn web application security, but tutorial quality varies. We reviewed 132 free security tutorials to examine topic coverage, authorship, and technical depth. Our analysis shows that most tutorials come from vendors and emphasize high-level explanations over concrete implementation guidance. Few tutorials provide complete runnable code examples or direct links to authoritative security resources such as the Open Web Application Security Project (OWASP), Common Weakness Enumeration (CWE), or Common Vulnerabilities and Exposures (CVE). We found that two visible signals help identify more useful tutorials: the presence of runnable code and direct links to official resources. These signals can help developers distinguish broad awareness material from tutorials that better support secure implementation.
format Preprint
id arxiv_https___arxiv_org_abs_2603_21556
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle A Survey of Web Application Security Tutorials
Chembakottu, Bhagya
Robillard, Martin P.
Cryptography and Security
Software Engineering
Developers rely on online tutorials to learn web application security, but tutorial quality varies. We reviewed 132 free security tutorials to examine topic coverage, authorship, and technical depth. Our analysis shows that most tutorials come from vendors and emphasize high-level explanations over concrete implementation guidance. Few tutorials provide complete runnable code examples or direct links to authoritative security resources such as the Open Web Application Security Project (OWASP), Common Weakness Enumeration (CWE), or Common Vulnerabilities and Exposures (CVE). We found that two visible signals help identify more useful tutorials: the presence of runnable code and direct links to official resources. These signals can help developers distinguish broad awareness material from tutorials that better support secure implementation.
title A Survey of Web Application Security Tutorials
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2603.21556