Engaging Company Developers in Security Research Studies: A Comprehensive Literature Review and Quantitative Survey

R Serafini, SA Horstmann, A Naiakshina - 33rd USENIX Security …, 2024 - usenix.org
Previous research demonstrated that company developers excel compared to freelancers
and computer science students, with the corporate environment significantly influencing …

On the recruitment of company developers for security studies: results from a qualitative interview study

R Serafini, M Gutfleisch, SA Horstmann… - … Symposium on Usable …, 2023 - usenix.org
To address the issue of participant recruitment for security developer studies, researchers
proposed using freelance online platforms or recruiting computer science (CS) students as …

[HTML][HTML] Addressing combinatorial experiments and scarcity of subjects by provably orthogonal and crossover experimental designs

F Massacci, A Papotti, R Paramitha - Journal of Systems and Software, 2024 - Elsevier
Abstract Context: Experimentation in Software and Security Engineering is a common
research practice, in particular with human subjects. Problem: The combinatorial nature of …

Pushed by Accident: A {Mixed-Methods} Study on Strategies of Handling Secret Information in Source Code Repositories

A Krause, JH Klemmer, N Huaman, D Wermke… - 32nd USENIX Security …, 2023 - usenix.org
Version control systems for source code, such as Git, are key tools in modern software
development. Many developers use services like GitHub or GitLab for collaborative software …

Write, Read, or Fix? Exploring Alternative Methods for Secure Development Studies

KR Fulton, J Lewis, N Malkin, ML Mazurek - Twentieth Symposium on …, 2024 - usenix.org
When studying how software developers perform security tasks, researchers often ask
participants to write code. These studies can be challenging because programming can be …

Studying Secure Coding in the Laboratory: Why, What, Where, How, and Who?

I Ryan, KJ Stol, U Roedig - 2023 IEEE/ACM 4th International …, 2023 - ieeexplore.ieee.org
Software security is an area of growing concern, with over 192,000 known vulnerabilities in
public software at the time of writing. Many aids to secure coding exist. Assessing the …