返回全部动态

开发者报告的软件安全测试挑战实证研究

原标题:Investigating Developer-Reported Software Security Testing Challenges

arXiv cs.SE一手来源研究质量 76

AI 摘要

该研究对 Stack Overflow 上 17,743 条与软件安全测试(SST)相关的提问进行大规模实证分析,人工标注出 582 条 SST 相关问题,并构建了包含 8 个类别、31 个子类别的分类体系。研究发现开发者面临的挑战不仅限于漏洞检测,还涉及安全发现解读与可靠性、测试指导与工具选择、认证授权测试、工具集成与自动化等,其中验证类问题需要更多技术背景和更长解决时间,误报常与可解释性问题共现。该成果可帮助研究者、从业者、教育者和工具厂商改进 SST 工具的可用性、文档、结果解读与修复支持。

以上摘要由 AI 生成,可能存在误差。事实请以原文为准。

正文节选

Investigating Developer-Reported Software Security Testing Challenges Abstract Context: Software security testing (SST) is essential for identifying vulnerabilities and improving software security. However, developers often face challenges when selecting tools, configuring test environments, interpreting security scanner outputs, testing authentication workflows, and acting on reported vulnerabilities in real-world software development practice. Objectives: This study empirically characterizes d


发布时间:2026-09-14 12:00
抓取时间:2026-09-14 13:54
来源机构:arXiv
阅读原文arxiv.org