Predicting Security-Vulnerable Developers Based on Their Techno-Behavioral Characteristics
M. D. J. S. Goonetillake,
Rangana Jayashanka and
S. V. Rathnayaka
Additional contact information
M. D. J. S. Goonetillake: School of Computing, University of Colombo, Sri Lanka
Rangana Jayashanka: School of Computing, University of Colombo, Sri Lanka
S. V. Rathnayaka: School of Computing, University of Colombo, Sri Lanka
International Journal of Information Security and Privacy (IJISP), 2022, vol. 16, issue 1, 1-26
Abstract:
Assigning developers for highly secured software projects requires identifying developers’ tendency to contribute towards vulnerable software codes called developer-centric security vulnerability to mitigate issues on human resource management, financial and project timelines. There are problems in assessing the previous codebases in evaluating the developer-centric security vulnerability level of each developer. Thus, this paper suggests a method to evaluate this through the techno-behavioral features of their previous projects. Consequently, we present results of an exploratory study of the developer-centric security vulnerability level prediction using a dataset of 1827 developers by logically selecting 13 techno-behavioral features. Our results depict that there is a correlation between techno-behavioral features and developer-centric security vulnerability with 89.46% accuracy. This model enables to predict developer-centric security vulnerability level of any developer if the required techno-behavioral features are available avoiding the analysis of his/her previous codebases.
Date: 2022
References: Add references at CitEc
Citations:
Downloads: (external link)
http://services.igi-global.com/resolvedoi/resolve. ... 018/IJISP.2022010103 (application/pdf)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:igg:jisp00:v:16:y:2022:i:1:p:1-26
Access Statistics for this article
International Journal of Information Security and Privacy (IJISP) is currently edited by Yassine Maleh
More articles in International Journal of Information Security and Privacy (IJISP) from IGI Global
Bibliographic data for series maintained by Journal Editor ().