Skip to main navigation Skip to search Skip to main content

An Exploratory Study on the Engineering of Security Features.

  • Kevin Hermann
  • , Sven Peldszus
  • , Jan-Philipp Steghöfer
  • , Thorsten Berger
  • Ruhr University Bochum
  • XITASO

Research output: Conference Article in Proceeding or Book/Report chapterArticle in proceedingsResearchpeer-review

Abstract

Software security is of utmost importance for most software systems. Developers must systematically select, plan, design, implement, and especially, maintain and evolve security features-functionalities to mitigate attacks or protect personal data such as cryptography or access control-to ensure the security of their software. Although security features are usually available in libraries, integrating security features requires writing and maintaining additional security-critical code. While there have been studies on the use of such libraries, surprisingly little is known about how developers engineer security features, how they select what security features to implement and which ones may require custom implementation, and the implications for maintenance. As a result, we currently rely on assumptions that are largely based on common sense or individual examples. However, to provide them with effective solutions, researchers need hard empirical data to understand what practitioners need and how they view security-data that we currently lack. To fill this gap, we contribute an exploratory study with 26 knowledgeable industrial participants. We study how security features of software systems are selected and engineered in practice, what their code- level characteristics are, and what challenges practitioners face. Based on the empirical data gathered, we provide insights into engineering practices and validate four common assumptions.
Original languageEnglish
Title of host publicationInternational Conference on Software Engineering (ICSE)
PublisherIEEE
Publication date2025
Pages2470-2482
DOIs
Publication statusPublished - 2025
Externally publishedYes
EventInternational Conference on Software Engineering - Rogers Centre, Ottowa, Canada
Duration: 27 Apr 20253 May 2025
Conference number: 47
https://conf.researchr.org/home/icse-2025

Conference

ConferenceInternational Conference on Software Engineering
Number47
LocationRogers Centre
Country/TerritoryCanada
CityOttowa
Period27/04/202503/05/2025
Internet address

Keywords

  • Software security
  • Security feature engineering
  • Empirical software engineering
  • Security libraries and integration
  • Maintenance and evolution of security features

Fingerprint

Dive into the research topics of 'An Exploratory Study on the Engineering of Security Features.'. Together they form a unique fingerprint.

Cite this