• DocumentCode
    3712432
  • Title

    A study of interactive code annotation for access control vulnerabilities

  • Author

    Tyler Thomas;Bill Chu;Heather Lipford;Justin Smith;Emerson Murphy-Hill

  • Author_Institution
    Department of Software and Information Systems, University of North Carolina at Charlotte, 28223, USA
  • fYear
    2015
  • Firstpage
    73
  • Lastpage
    77
  • Abstract
    While there are a variety of existing tools to help detect security vulnerabilities in code, they are seldom used by developers due to the time or security expertise required. We are investigating techniques integrated within the IDE to help developers detect and mitigate security vulnerabilities. In this paper, we examine using interactive annotation for access control vulnerabilities. We evaluated whether developers could indicate access control logic using interactive annotation and understand the vulnerabilities reported as a result. Our study indicates that developers can easily find and annotate access control logic but can struggle to use our tool to trace the cause of the vulnerability. Our results provide design guidance for improving the interaction and communication of such security tools with developers.
  • Keywords
    "Databases","Chlorine","Software"
  • Publisher
    ieee
  • Conference_Titel
    Visual Languages and Human-Centric Computing (VL/HCC), 2015 IEEE Symposium on
  • Type

    conf

  • DOI
    10.1109/VLHCC.2015.7357200
  • Filename
    7357200