arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

调查开发者报告的软件安全测试挑战

Investigating Developer-Reported Software Security Testing Challenges

Md Erfan, Ahmed Ryan, Md Rayhanur Rahman

arXiv 2609.12008首次发表:更新:

发表机构

University of Alabama(阿拉巴马大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究通过分析Stack Overflow上的17,743个问题,识别出582个软件安全测试相关讨论,构建了8类31子类的挑战分类法,发现开发者主要面临结果解释、工具选择、认证测试和集成等挑战,且这些挑战随时间演变,为改进SST实践提供了依据。

AI 中文摘要

软件安全测试(SST)对于识别漏洞和提高软件安全性至关重要,但开发者在选择工具、配置测试环境、解释扫描器输出、测试认证工作流以及处理报告的漏洞时,常常面临实际挑战。本研究通过实证方法刻画了Stack Overflow(SO)讨论中开发者报告的SST挑战,并考察了这些挑战的普遍性、难度、时间演变、共现性以及分类法的稳定性。我们分析了使用SST相关关键词收集的17,743个SO问题。通过人工标注,我们识别出582个与SST相关的问题,并构建了一个包含8个类别和31个子类别的分类法。随后,我们使用普遍性、难度、相关性、时间趋势、共现性和保留样本稳定性分析对这些挑战进行了分析。结果表明,开发者经常讨论安全发现的解释与可靠性、安全测试指导与工具选择、认证与授权测试,以及安全工具集成与自动化。与验证相关的挑战通常需要更多的技术背景和更长的解决时间。安全发现的解释和与修复相关的可操作性显示出随时间增长的趋势。共现性分析显示,误报经常与可解释性同时出现,而集成挑战则经常与工具建议和文档/资源同时出现。总体而言,开发者报告的SST挑战超出了漏洞检测的范围,还包括工作流、配置、解释和修复方面的问题。这些发现可以帮助研究人员、从业者、教育工作者和工具提供商改进SST的可用性、文档、结果解释和修复支持。

英文摘要

Software security testing (SST) is essential for identifying vulnerabilities and improving software security, but developers often face practical challenges when selecting tools, configuring test environments, interpreting scanner outputs, testing authentication workflows, and acting on reported vulnerabilities. This study empirically characterizes developer-reported SST challenges in Stack Overflow (SO) discussions and examines their prevalence, difficulty, temporal evolution, co-occurrence, and taxonomy stability. We analyze 17,743 SO questions collected using SST-related keywords. Through manual labeling, we identify 582 SST-related questions and construct a taxonomy of 8 categories and 31 subcategories. We then analyze these challenges using prevalence, difficulty, correlation, temporal trend, co-occurrence, and held-out stability analyses. The results show that developers frequently discuss security finding interpretation and reliability, security testing guidance and tool selection, authentication and authorization testing, and security tool integration and automation. Validation-related challenges often require more technical context and longer resolution time. Security finding interpretation and remediation-related actionability show increasing trends over time. Co-occurrence analysis shows that false positives frequently appear with explainability, while integration challenges often appear with tool suggestions and documentation/resources. Overall, developer-reported SST challenges extend beyond vulnerability detection and include workflow, configuration, interpretation, and remediation concerns. These findings can help researchers, practitioners, educators, and tool providers improve SST usability, documentation, result interpretation, and remediation support.

Comments34 pages

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑