Towards Immediate Feedback for Security Relevant Code in Development Environments
Markus Haug Ana Cristina Franco Da Silva, Stefan Wagner

TL;DR
This paper proposes an integrated, user-centered system for providing immediate security vulnerability feedback within IDEs, aiming to improve developers' ability to write secure code efficiently.
Contribution
It introduces a novel approach to deliver real-time security feedback in IDEs, incorporating developer feedback to adapt notifications and enhance understandability.
Findings
Supports continuous immediate security feedback in IDEs
Enhances understandability of security notifications
Adapts to individual developer preferences
Abstract
Nowadays, the correct use of cryptography libraries is essential to ensure the necessary information security in different kinds of applications. A common practice in software development is the use of static application security testing (SAST) tools to analyze code regarding security vulnerabilities. Most of these tools are designed to run separately from development environments. Their results are extensive lists of security notifications, which software developers have to inspect manually in a time-consuming follow-up step. To support developers in their tasks of developing secure code, we present an approach for providing them with continuous immediate feedback of SAST tools in integrated development environments (IDEs). Our approach also considers the understandability of security notifications and aims for a user-centered approach that leverages developers' feedback to build an…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSoftware Engineering Research · Advanced Malware Detection Techniques · Information and Cyber Security
