Skip to main navigation Skip to search Skip to main content

A Qualitative Study of Dependency Management and Its Security Implications

Research output: Chapter in Book / Report / Conference proceedingConference contributionAcademicpeer-review

Abstract

Several large scale studies on the Maven, NPM, and Android ecosystems point out that many developers do not often update their vulnerable software libraries thus exposing the user of their code to security risks. The purpose of this study is to qualitatively investigate the choices and the interplay of functional and security concerns on the developers' overall decision-making strategies for selecting, managing, and updating software dependencies.

We run 25 semi-structured interviews with developers of both large and small-medium enterprises located in nine countries. All interviews were transcribed, coded, and analyzed according to applied thematic analysis. They highlight the trade-offs that developers are facing and that security researchers must understand to provide effective support to mitigate vulnerabilities (for example bundling security fixes with functional changes might hinder adoption due to lack of resources to fix functional breaking changes).

We further distill our observations to actionable implications on what algorithms and automated tools should achieve to effectively support (semi-)automatic dependency management.
Original languageEnglish
Title of host publicationCCS '20: Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security
PublisherAssociation for Computing Machinery
Pages1513–1531
ISBN (Electronic)9781450370899
ISBN (Print)9781450370899
DOIs
Publication statusPublished - 30 Oct 2020
Externally publishedYes
Event27th ACM SIGSAC Conference on Computer and Communications Security, CCS 2020 - Virtual, Online, United States
Duration: 9 Nov 202013 Nov 2020

Publication series

NameProceedings of the ACM Conference on Computer and Communications Security
ISSN (Print)1543-7221

Conference

Conference27th ACM SIGSAC Conference on Computer and Communications Security, CCS 2020
Country/TerritoryUnited States
CityVirtual, Online
Period9/11/2013/11/20

Funding

FundersFunder number
European Network for Cyber Security675320
Horizon 2020 Framework Programme
European Commission830929

    VU Research Profile

    • Connected World
    • Governance for Society

    Fingerprint

    Dive into the research topics of 'A Qualitative Study of Dependency Management and Its Security Implications'. Together they form a unique fingerprint.

    Cite this