Unhelpful assumptions in software security research

dc.contributor.authorRyan, Itaen
dc.contributor.authorRoedig, Utzen
dc.contributor.authorStol, Klaas-Janen
dc.contributor.funderScience Foundation Irelanden
dc.date.accessioned2023-11-29T10:13:37Z
dc.date.available2023-11-29T10:13:37Z
dc.date.issued2023-11-21en
dc.description.abstractIn the study of software security many factors must be considered. Once venturing beyond the simplest of laboratory experiments, the researcher is obliged to contend with exponentially complex conditions. Software security has been shown to be affected by priming, tool usability, library documentation, organisational security culture, the content and format of internet resources, IT team and developer interaction, Internet search engine ordering, developer personality, security warning placement, mentoring, developer experience and more. In a systematic review of software security papers published since 2016, we have identified a number of unhelpful assumptions that are commonly made by software security researchers. In this paper we list these assumptions, describe why they sometimes do not reflect reality, and suggest implications for researchers.en
dc.description.statusPeer revieweden
dc.description.versionPublished Versionen
dc.format.mimetypeapplication/pdfen
dc.identifier.citationRyan, I., Roedig, U and Stol, K.-J. (2023) 'Unhelpful assumptions in software security research', Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, Copenhagen, Denmark, 26-30 November, pp. 3460-3474. doi: 10.1145/3576915.3623122en
dc.identifier.doi10.1145/3576915.3623122en
dc.identifier.endpage3474en
dc.identifier.startpage3460en
dc.identifier.urihttps://hdl.handle.net/10468/15271
dc.language.isoenen
dc.publisherAssociation for Computing Machineryen
dc.relation.ispartofProceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Securityen
dc.relation.ispartofACM CCS 2023, 26-30 November, Copenhagen, Denmarken
dc.relation.projectinfo:eu-repo/grantAgreement/SFI/SFI Centres for Research Training Programme::Data and ICT Skills for the Future/18/CRT/6222/IE/SFI Centre for Research Training in Advanced Networks for Sustainable Societies/en
dc.relation.projectinfo:eu-repo/grantAgreement/SFI/SFI Research Centres Programme::Phase 2/13/RC/2077_P2/IE/CONNECT_Phase 2/en
dc.relation.projectinfo:eu-repo/grantAgreement/SFI/SFI Research Centres Programme::Phase 2/13/RC/2094_P2/IE/Lero_Phase 2/en
dc.relation.projectinfo:eu-repo/grantAgreement/SFI/SFI Starting Investigator Research Grant (SIRG)/15/SIRG/3293/IE/Software Development with Alternative Workforces/en
dc.rights© 2023, the Authors. This work is licensed under a Creative Commons Attribution International 4.0 License.en
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/en
dc.subjectSoftware securityen
dc.subjectSecure software developmenten
dc.titleUnhelpful assumptions in software security researchen
dc.typeConference itemen
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
CCS_Assumptions_Paper-Final.pdf
Size:
504.27 KB
Format:
Adobe Portable Document Format
Description:
Published Version
License bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
2.71 KB
Format:
Item-specific license agreed upon to submission
Description: