TY - GEN
T1 - Barriers to Using Static Application Security Testing (SAST) Tools
T2 - 39th ACM/IEEE International Conference on Automated Software Engineering Workshops, ASEW 2024
AU - Wadhams, Zachary
AU - Izurieta, Clemente
AU - Reinhold, Ann Marie
N1 - Publisher Copyright:
© 2024 ACM.
PY - 2024/10/27
Y1 - 2024/10/27
N2 - Developers face a challenging problem with no clear solution. Modern software breaches can wreak havoc on businesses and individuals alike. With code vulnerabilities being a leading cause, securing applications must be a priority for developers. Static Application Security Testing (SAST) has the potential to harden applications by assisting in the identification and resolution of security vulnerabilities. Despite this, many development teams have not adopted SAST tools into their environment. In this paper, we survey the recent literature to uncover why some developers are apprehensive towards SAST and identify what specific problems they encounter when using it. We found a variety of usability problems developers face when using SAST. Some are inherent of the tool and ultimately require some level of developer investment while others are tool shortcomings that SAST tool creators must address. Ultimately, we argue that in order to drive widespread adoption and consistent SAST usage, developers will need to embrace that some investment is required. Simultaneously, developers will be more likely to integrate SAST tools into their workflows if the creators of SAST tools simplify many aspects related to tool usage. Surmounting the primary obstacles preventing the adoption of SAST requires full consideration of both the technical and human factors.
AB - Developers face a challenging problem with no clear solution. Modern software breaches can wreak havoc on businesses and individuals alike. With code vulnerabilities being a leading cause, securing applications must be a priority for developers. Static Application Security Testing (SAST) has the potential to harden applications by assisting in the identification and resolution of security vulnerabilities. Despite this, many development teams have not adopted SAST tools into their environment. In this paper, we survey the recent literature to uncover why some developers are apprehensive towards SAST and identify what specific problems they encounter when using it. We found a variety of usability problems developers face when using SAST. Some are inherent of the tool and ultimately require some level of developer investment while others are tool shortcomings that SAST tool creators must address. Ultimately, we argue that in order to drive widespread adoption and consistent SAST usage, developers will need to embrace that some investment is required. Simultaneously, developers will be more likely to integrate SAST tools into their workflows if the creators of SAST tools simplify many aspects related to tool usage. Surmounting the primary obstacles preventing the adoption of SAST requires full consideration of both the technical and human factors.
KW - Barriers
KW - Developers
KW - Literature Review
KW - SAST
KW - Static Application Security Testing
KW - Usability
UR - https://www.scopus.com/pages/publications/85213361354
UR - https://www.mendeley.com/catalogue/3b242775-18e2-3979-94e3-58cc344731e2/
U2 - 10.1145/3691621.3694947
DO - 10.1145/3691621.3694947
M3 - Conference contribution
AN - SCOPUS:85213361354
T3 - Proceedings - 2024 39th ACM/IEEE International Conference on Automated Software Engineering Workshops, ASEW 2024
SP - 161
EP - 166
BT - Proceedings - 2024 39th ACM/IEEE International Conference on Automated Software Engineering Workshops, ASEW 2024
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 28 October 2024 through 1 November 2024
ER -