How far are German companies in improving security through static program analysis tools?
Goran Piskachev, Stefan Dziwok, Thorsten Koch, Sven Merschjohan, Eric, Bodden

TL;DR
This study investigates the adoption and usage of static program analysis tools for security in German companies, revealing limited and inconsistent use, with cultural factors influencing tool configuration and security practices.
Contribution
It provides new insights into company culture and processes affecting SPA tool adoption and highlights gaps in security checks during software releases.
Findings
Only half of surveyed companies use SPA tools.
Free tools are more popular among developers.
Automatic security checks are rarely performed on each release.
Abstract
As security becomes more relevant for many companies, the popularity of static program analysis (SPA) tools is increasing. In this paper, we target the use of SPA tools among companies in Germany with a focus on security. We give insights on the current issues and the developers' willingness to configure the tools to overcome these issues. Compared to previous studies, our study considers the companies' culture and processes for using SPA tools. We conducted an online survey with 256 responses and semi-structured interviews with 17 product owners and executives from multiple companies. Our results show a diversity in the usage of tools. Only half of our survey participants use SPA tools. The free tools tend to be more popular among software developers. In most companies, software developers are encouraged to use free tools, whereas commercial tools can be requested. However, the product…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Software Engineering Research · Advanced Malware Detection Techniques
