Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Paul Lunn

dblp:313/3463 · DBLP profile ↗
← Back
1ranked-venue papers
0as first author
1since 2021 · last 2022
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Usable security · 67% Systems and software security · 33%
Software engineering, system software, and programming languages
1 paper
Empirical software engineering · 100%

Topics — the 4 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Usable security › security behavior
developer security behavior
0.612022
The Case for Adaptive Security Interventions · ACM Trans. Softw. Eng. Methodol. 2022
Systems and software security › secure software development
secure coding
0.612022
The Case for Adaptive Security Interventions · ACM Trans. Softw. Eng. Methodol. 2022
Usable security
security interventions
0.612022
The Case for Adaptive Security Interventions · ACM Trans. Softw. Eng. Methodol. 2022
Empirical software engineering
developer studies
0.212022
The Case for Adaptive Security Interventions · ACM Trans. Softw. Eng. Methodol. 2022

Methods — techniques the papers use, named apart from their topics

meta-analysis · 1.1cognitive psychology · 1.1
YearPublicationVenuePosition
2022 The Case for Adaptive Security Interventions
abstract
Despite the availability of various methods and tools to facilitate secure coding, developers continue to write code that contains common vulnerabilities. It is important to understand why technological advances do not sufficiently facilitate developers in writing secure code. To widen our understanding of developers' behaviour, we considered the complexity of the security decision space of developers using theory from cognitive and social psychology. Our interdisciplinary study reported in this article (1) draws on the psychology literature to provide conceptual underpinnings for three categories of impediments to achieving security goals, (2) reports on an in-depth meta-analysis of existing software security literature that identified a catalogue of factors that influence developers' security decisions, and (3) characterises the landscape of existing security interventions that are available to the developer during coding and identifies gaps. Collectively, these show that different forms of impediments to achieving security goals arise from different contributing factors. Interventions will be more effective where they reflect psychological factors more sensitively and marry technical sophistication, psychological frameworks, and usability. Our analysis suggests “adaptive security interventions” as a solution that responds to the changing security needs of individual developers and a present a proof-of-concept tool to substantiate our suggestion.
Irum Rauf, Marian Petre, Thein Tun, Tamara Lopez, Paul Lunn, Dirk van der Linden, John N. Towse, Helen Sharp, Mark Levine, Awais Rashid, Bashar Nuseibeh
ACM Trans. Softw. Eng. Methodol.5