论文标题

德国公司通过静态程序分析工具提高安全性有多远?

How far are German companies in improving security through static program analysis tools?

论文作者

Piskachev, Goran, Dziwok, Stefan, Koch, Thorsten, Merschjohan, Sven, Bodden, Eric

论文摘要

随着对许多公司的安全性变得更加相关,静态程序分析(SPA)工具的普及正在增加。在本文中,我们针对德国公司之间使用水疗工具的目的,重点是安全。我们对当前问题以及开发人员配置工具以克服这些问题的意愿提供见解。与以前的研究相比,我们的研究考虑了公司使用水疗工具的文化和过程。我们进行了一项在线调查,对来自多家公司的17位产品所有者和高管进行了256次回复和半结构化访谈。我们的结果表明,工具的使用情况有多样性。我们的调查参与者中只有一半使用水疗工具。免费工具在软件开发人员中往往更受欢迎。在大多数公司中,鼓励软件开发人员使用免费工具,而可以要求商业工具。但是,我们的采访中的产品所有者和高管报告说,他们的开发人员不要求新工具。我们还发现,使用工具的自动安全检查在每个版本上很少执行。

As security becomes more relevant for many companies, the popularity of static program analysis (SPA) tools is increasing. In this paper, we target the use of SPA tools among companies in Germany with a focus on security. We give insights on the current issues and the developers' willingness to configure the tools to overcome these issues. Compared to previous studies, our study considers the companies' culture and processes for using SPA tools. We conducted an online survey with 256 responses and semi-structured interviews with 17 product owners and executives from multiple companies. Our results show a diversity in the usage of tools. Only half of our survey participants use SPA tools. The free tools tend to be more popular among software developers. In most companies, software developers are encouraged to use free tools, whereas commercial tools can be requested. However, the product owners and executives in our interviews reported that their developers do not request new tools. We also find out that automatic security checks with tools are rarely performed on each release.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源