Aug 2026· Message Understanding Conference· pp. 88-112· 0 citations· 29 references
Computer Science
TL;DR
This work conducted semi-structured interviews with professional software developers and categorized the threats they discussed using the STRIDE threat modeling approach, finding distinct roles through which developers engage with security threats, including collaborator, end-user, tool-user, and business roles.
Abstract
While end-user decisions primarily impact their own data, software developers’ security behavior can affect millions of users’ data. To understand developers’ decision-making processes, we explored their mental models of security threats. We conducted semi-structured interviews, based on Wash [89] with 37 professional software developers and categorized the threats they discussed using the STRIDE threat modeling approach. We describe three mental models of threat types: Developers focused on threats as exploits, vulnerabilities, or the impact of the threat. Besides development-specific threats (e.g., injection-, denial-of-service attacks), they also expressed concerns about end-user threats (e.g., malware, phishing attacks). We identified mitigation strategies used across threats: soft skills (e.g., communication), hard skills (e.g., security tools and libraries), and organizational strategies (e.g., IT infrastructure). We also discovered distinct roles through which developers engage with security threats, including collaborator, end-user, tool-user, and business roles. We provide recommendations on supporting developers in managing security risks and decisions.
It is concluded that web application security requires continuous assessment and proactive security practices throughout the software development lifecycle, and adopting OWASP guidelines and implementing effective security controls can significantly enhance the protection and resilience of modern web applications.
S. Banu, H. Shanmatha, Mehdi Gheisari et al.· BOHR International Journal o...· 0 citations
Overall, developer-reported SST challenges extend beyond vulnerability detection and include workflow, configuration, interpretation, and remediation concerns and can help researchers, practitioners, educators, and tool providers improve SST usability, documentation, result interpretation, and remediation support.
Md Erfan, A. Ryan, Md. Rayhanur Rahman· 0 citations
- The rapid adoption of agentic artificial intelligence has transformed large language models into agents that can discover tools, access resources, process information, and execute actions in external environments. The Model Context Protocol (MCP) supports this transformation by enabling standardized interaction betwe...
Khalid D. Muhammed, David Chinonso Anih· Iconic research and engineer...· 0 citations
AI coding assistants are rapidly transforming software development, but are known to produce insecure code. Prior work has measured whether AI-assisted developers produce secure code, but less is known about how they evaluate AI-generated code: whether they can identify vulnerabilities, what cues they use, and how trus...
Hamza Khalid, Ronald E. Thompson, A. Sabater et al.· 0 citations
The number of recorded vulnerabilities in software continues to rise, despite attempts to improve secure coding practice. Much software security research focuses on software developers’ abilities, tools and motivations. However, software security budgets and priorities ultimately derive from an organisation's senior ma...
Ita Ryan, U. Roedig, Klaas-Jan Stol· ACM Transactions on Software...· 0 citations
Large Language Models (LLMs) and foundation models are increasingly deployed in security-critical and high-impact settings, including healthcare, cybersecurity, software engineering, and intelligent infrastructure. Their open-ended interfaces and multimodal capabilities create new attack surfaces, where prompt injectio...
Abdullahi Chowdhury, Tasmim Jamal Joti, M. Afikuzzaman et al.· International Journal of Inf...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.