Vulnerably (Mis)Configured? Exploring 10 Years of Developers' Q&As on Stack Overflow

Richard May, Christian Biermann, Xenia M. Zerweck, Kai Ludwig, Jacob Krüger, Thomas Leich

Onderzoeksoutput: Hoofdstuk in Boek/Rapport/CongresprocedureConferentiebijdrageAcademicpeer review

2 Citaten (Scopus)
157 Downloads (Pure)

Samenvatting

The increasing number of attacks exploiting system vulnerabilities in recent years underpins the growing importance of security; especially for software comprising configuration options that may cause unintended vulnerabilities. So, not surprisingly, developers discuss secure software configurations extensively, for instance, via community-question-answering systems like Stack Overflow. In this exploratory study, we analyzed 651 Stack Overflow posts from 2013 until 2022 to investigate what vulnerabilities in the context of configuring software developers discuss. We employed a manual data analysis and automated topic modeling using Latent Dirichlet Allocation to identify and classify relevant topics and contexts. Our results show that vulnerabilities in the context of configuring receive more and more interest, with most posts discussing issues related to faulty security configurations and dependencies causing vulnerabilities that could be or have actually been exploited. Overall, we contribute insights into configuration and security issues that developers experience in the real world. Such insights help researchers and practitioners understand and resolve these issues, thereby guiding future improvements.
Originele taal-2Engels
TitelVaMoS '24
SubtitelProceedings of the 18th International Working Conference on Variability Modelling of Software-Intensive Systems
RedacteurenTimo Kehrer, Marianne Huchard, Leopoldo Teixeira, Christian Birchler
UitgeverijAssociation for Computing Machinery, Inc
Pagina's112-122
Aantal pagina's11
ISBN van elektronische versie979-8-4007-0877-0
DOI's
StatusGepubliceerd - 7 feb. 2024
Evenement18th International Working Conference on Variability Modelling of Software-Intensive Systems, VaMoS 2024 - Bern, Zwitserland
Duur: 7 feb. 20249 feb. 2024

Congres

Congres18th International Working Conference on Variability Modelling of Software-Intensive Systems, VaMoS 2024
Verkorte titelVaMoS 2024
Land/RegioZwitserland
StadBern
Periode7/02/249/02/24

Vingerafdruk

Duik in de onderzoeksthema's van 'Vulnerably (Mis)Configured? Exploring 10 Years of Developers' Q&As on Stack Overflow'. Samen vormen ze een unieke vingerafdruk.

Citeer dit