Feb. 1, 2009 to Feb. 7, 2009
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/ACHI.2009.18
Modern software systems are difficult to test due to their distributed nature, and increased security complicates testing even further. Our hypothesis is that some security vulnerabilities are actually introduced due to developers’ need to facilitate testing that software requirements have been implemented correctly. If these temporary security vulnerabilities are not removed before the software is delivered, there is a great risk that they may become fielded security vulnerabilities.In this paper, we study the relationship between such security vulnerabilities and developers' need to improve the testability of an application to facilitate unit and integration testing. We trace detected vulnerabilities to characteristics of the software that made testing difficult and therefore led to testability improvements. We discuss how the need to increase testability may relate to a form of developer usability, and what the ways of dealing with the problem of security vulnerabilities as a consequence of increasing testability are.
Security, testability, usability
Kaarina Karppinen, Lyly Yonkwa, Mikael Lindvall, "Why Developers Insert Security Vulnerabilities into Their Code", ACHI, 2009, International Conference on Advances in Computer-Human Interaction, International Conference on Advances in Computer-Human Interaction 2009, pp. 289-294, doi:10.1109/ACHI.2009.18