2019 IEEE/ACM 41st International Conference on Software Engineering: Software Engineering in Society (ICSE-SEIS) 2019
DOI: 10.1109/icse-seis.2019.00012
|View full text |Cite
|
Sign up to set email alerts
|

An Anatomy of Security Conversations in Stack Overflow

Abstract: As software-intensive digital systems become an integral part of modern life, ensuring that these systems are developed to satisfy security and privacy requirements is an increasingly important societal concern. This paper examines how secure coding practice is supported on Stack Overflow. Although there are indications that on-line environments are not robust or accurate sources of security information, they are used by large numbers of developers. Findings demonstrate that developers use conversation within … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

1
25
0

Year Published

2020
2020
2023
2023

Publication Types

Select...
4
3

Relationship

1
6

Authors

Journals

citations
Cited by 27 publications
(26 citation statements)
references
References 31 publications
(46 reference statements)
1
25
0
Order By: Relevance
“…Researchers have also studied the topics developers talk about; including analysis with natural language processing techniques (NLP) [5,16,18,56,71,76] and manual qualitative techniques [18,36,43,44,47,48,52,55,71]. For example, an analysis of questions about Puppet, a configuration language tool, shows a need to support Puppet syntax error finding [55].…”
Section: Stack Overflowmentioning
confidence: 99%
See 1 more Smart Citation
“…Researchers have also studied the topics developers talk about; including analysis with natural language processing techniques (NLP) [5,16,18,56,71,76] and manual qualitative techniques [18,36,43,44,47,48,52,55,71]. For example, an analysis of questions about Puppet, a configuration language tool, shows a need to support Puppet syntax error finding [55].…”
Section: Stack Overflowmentioning
confidence: 99%
“…It attracts a wide range of developers who ask questions about programming, security, and data management [18,56,76]. SO's dataset has been heavily used for research on such topics as: what factors makes it a successful Q&A platform [45], security issues developers face and how they interact and build knowledge around it [43,76], and the negative impact of SO code snippets in software security [2].…”
Section: Introductionmentioning
confidence: 99%
“…The interactions and conversations we have observed within office settings [9] and comment streams on Stack Overflow [7], [8] suggest that secure coding practice is supported in both kinds of environment through personal networks of practice [14] that operate within larger environments. Online, in websites like Stack Overflow, such networks operate within the comment streams attached to question and answer posts.…”
Section: Network Of Practicementioning
confidence: 99%
“…It takes time to learn and understand good practices, and the shifting landscape of threats requires ongoing attention to ensure that mechanisms remain effective and up-to-date. Security tagged posts on Stack Overflow reflect this, and often remain active for months or even years after an answer is accepted [8]. Ongoing activity may be primarily curatorial-links might be kept up-to-date or added to dictionary entries or other documents, or the language of the question and answer posts might be refined for clarity.…”
Section: Look For Tended Posts and Comment Streamsmentioning
confidence: 99%
See 1 more Smart Citation