DocumentCode
3712432
Title
A study of interactive code annotation for access control vulnerabilities
Author
Tyler Thomas;Bill Chu;Heather Lipford;Justin Smith;Emerson Murphy-Hill
Author_Institution
Department of Software and Information Systems, University of North Carolina at Charlotte, 28223, USA
fYear
2015
Firstpage
73
Lastpage
77
Abstract
While there are a variety of existing tools to help detect security vulnerabilities in code, they are seldom used by developers due to the time or security expertise required. We are investigating techniques integrated within the IDE to help developers detect and mitigate security vulnerabilities. In this paper, we examine using interactive annotation for access control vulnerabilities. We evaluated whether developers could indicate access control logic using interactive annotation and understand the vulnerabilities reported as a result. Our study indicates that developers can easily find and annotate access control logic but can struggle to use our tool to trace the cause of the vulnerability. Our results provide design guidance for improving the interaction and communication of such security tools with developers.
Keywords
"Databases","Chlorine","Software"
Publisher
ieee
Conference_Titel
Visual Languages and Human-Centric Computing (VL/HCC), 2015 IEEE Symposium on
Type
conf
DOI
10.1109/VLHCC.2015.7357200
Filename
7357200
Link To Document