Towards Immediate Feedback for Security Relevant Code in Development Environments

Nowadays, the correct use of cryptography libraries is essential to ensure the necessary information security in different kinds of applications. A common practice in software development is the use of static application security testing (SAST) tools to analyze code regarding security vulnerabilities. Most of these tools are designed to run separately from development environments. Their results are extensive lists of security notifications, which software developers have to inspect manually in a time-consuming follow-up step. To support developers in their tasks of developing secure code, we present an approach for providing them with continuous immediate feedback of SAST tools in integrated development environments (IDEs). Our approach also considers the understandability of security notifications and aims for a user-centered approach that leverages developers' feedback to build an adaptive system tailored to each individual developer.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/23/2018

Evaluation of Static Analysis Tools for Finding Vulnerabilities in Java and C/C++ Source Code

It is quite common for security testing to be delayed until after the so...
research
05/23/2018

Evaluation of Static Analysis Tools for Finding Vulunerbailities in Java and C/C++ Source Code

It is quite common for security testing to be delayed until after the so...
research
02/04/2021

Parallelware Tools: An Experimental Evaluation on POWER Systems

Static code analysis tools are designed to aid software developers to bu...
research
05/11/2018

Statically Verifying Continuous Integration Configurations

Continuous Integration (CI) testing is a popular software development te...
research
08/30/2023

Collaborative, Code-Proximal Dynamic Software Visualization within Code Editors

Software visualizations are usually realized as standalone and isolated ...
research
11/04/2022

Better Call Saltzer & Schroeder: A Retrospective Security Analysis of SolarWinds & Log4j

Saltzer & Schroeder's principles aim to bring security to the design of ...

Please sign up or login with your details

Forgot password? Click here to reset