Publication:

Less is more: Supporting developers in vulnerability detection during code review

Date

Date

Date
2022
Conference or Workshop Item
Published version

Citations

Citation copied

Braz, L., Aeberhard, C., Çalikli, G., & Bacchelli, A. (2022). Less is more: Supporting developers in vulnerability detection during code review. 1317–1329. https://doi.org/10.1145/3510003.3511560

Abstract

Abstract

Abstract

Reviewing source code from a security perspective has proven to be a difficult task. Indeed, previous research has shown that developers often miss even popular and easy-to-detect vulnerabilities during code review. Initial evidence suggests that a significant cause may lie in the reviewers' mental attitude and common practices.

In this study, we investigate whether and how explicitly asking developers to focus on security during a code review affects the detection of vulnerabilities. Furthermore, we evaluate the effect of providing

Metrics

Downloads

46 since deposited on 2023-03-09
Acq. date: 2025-11-14

Views

96 since deposited on 2023-03-09
Acq. date: 2025-11-14

Additional indexing

Creators (Authors)

Event Title

Event Title

Event Title
ICSE '22: 44th International Conference on Software Engineering

Event Location

Event Location

Event Location
Pittsburgh Pennsylvania

Event Start Date

Event Start Date

Event Start Date
2022-06-21

Event End Date

Event End Date

Event End Date
2022-06-29

Publisher

Publisher

Publisher

Page range/Item number

Page range/Item number

Page range/Item number
1317

Page end

Page end

Page end
1329

Item Type

Item Type

Item Type
Conference or Workshop Item

Dewey Decimal Classifikation

Dewey Decimal Classifikation

Dewey Decimal Classifikation

Scope

Scope

Scope
Discipline-based scholarship (basic research)

Language

Language

Language
English

Date available

Date available

Date available
2023-03-09

ISBN or e-ISBN

ISBN or e-ISBN

ISBN or e-ISBN
9781450392211

OA Status

OA Status

OA Status
Hybrid

Free Access at

Free Access at

Free Access at
Unspecified

Other Identification Number

Other Identification Number

Other Identification Number
merlin-id:23369

Metrics

Downloads

46 since deposited on 2023-03-09
Acq. date: 2025-11-14

Views

96 since deposited on 2023-03-09
Acq. date: 2025-11-14

Citations

Citation copied

Braz, L., Aeberhard, C., Çalikli, G., & Bacchelli, A. (2022). Less is more: Supporting developers in vulnerability detection during code review. 1317–1329. https://doi.org/10.1145/3510003.3511560

Hybrid Open Access
Loading...
Thumbnail Image

Files

Files

Files
Files available to download:1

Files

Files

Files
Files available to download:1
Loading...
Thumbnail Image