{"id":"https://openalex.org/W2170847850","doi":"https://doi.org/10.1109/achi.2009.18","title":"Why Developers Insert Security Vulnerabilities into Their Code","display_name":"Why Developers Insert Security Vulnerabilities into Their Code","publication_year":2009,"publication_date":"2009-02-01","ids":{"openalex":"https://openalex.org/W2170847850","doi":"https://doi.org/10.1109/achi.2009.18","mag":"2170847850"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/achi.2009.18","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5022440753","display_name":"Kaarina Karppinen","orcid":null},"institutions":[{"id":"https://openalex.org/I87653560","display_name":"VTT Technical Research Centre of Finland","ror":"https://ror.org/04b181w54","country_code":"FI","type":"nonprofit","lineage":["https://openalex.org/I4210089493","https://openalex.org/I87653560"]}],"countries":["FI"],"is_corresponding":false,"raw_author_name":"Kaarina Karppinen","raw_affiliation_strings":["VTT Technical Research Centre of Finland, Finland"],"affiliations":[{"raw_affiliation_string":"VTT Technical Research Centre of Finland, Finland","institution_ids":["https://openalex.org/I87653560"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5087160315","display_name":"Lyly Yonkwa","orcid":null},"institutions":[{"id":"https://openalex.org/I97750245","display_name":"Software (Spain)","ror":"https://ror.org/02ethns06","country_code":"ES","type":"company","lineage":["https://openalex.org/I4210087817","https://openalex.org/I97750245"]}],"countries":["ES"],"is_corresponding":false,"raw_author_name":"Lyly Yonkwa","raw_affiliation_strings":["Fraunhofer Center of Experimental Software"],"affiliations":[{"raw_affiliation_string":"Fraunhofer Center of Experimental Software","institution_ids":["https://openalex.org/I97750245"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5070426245","display_name":"Mikael Lindvall","orcid":null},"institutions":[{"id":"https://openalex.org/I4210087817","display_name":"Software (Germany)","ror":"https://ror.org/004g36n56","country_code":"DE","type":"company","lineage":["https://openalex.org/I4210087817"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Mikael Lindvall","raw_affiliation_strings":["Fraunhofer Center of Experimental Software, Germany"],"affiliations":[{"raw_affiliation_string":"Fraunhofer Center of Experimental Software, Germany","institution_ids":["https://openalex.org/I4210087817"]}]}],"institution_assertions":[],"countries_distinct_count":3,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.492,"has_fulltext":true,"fulltext_origin":"ngrams","cited_by_count":3,"citation_normalized_percentile":{"value":0.438963,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":74,"max":77},"biblio":{"volume":null,"issue":null,"first_page":"289","last_page":"294"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9974,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9974,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9971,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10430","display_name":"Software Engineering Techniques and Practices","score":0.9966,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/secure-coding","display_name":"Secure coding","score":0.8615073},{"id":"https://openalex.org/keywords/security-bug","display_name":"Security bug","score":0.73750246},{"id":"https://openalex.org/keywords/security-testing","display_name":"Security Testing","score":0.7320581},{"id":"https://openalex.org/keywords/vulnerability-management","display_name":"Vulnerability management","score":0.5507721},{"id":"https://openalex.org/keywords/unit-testing","display_name":"Unit testing","score":0.47757107}],"concepts":[{"id":"https://openalex.org/C22680326","wikidata":"https://www.wikidata.org/wiki/Q7444867","display_name":"Secure coding","level":5,"score":0.8615073},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7415889},{"id":"https://openalex.org/C131275738","wikidata":"https://www.wikidata.org/wiki/Q7445023","display_name":"Security bug","level":5,"score":0.73750246},{"id":"https://openalex.org/C195518309","wikidata":"https://www.wikidata.org/wiki/Q13424265","display_name":"Security testing","level":5,"score":0.7320581},{"id":"https://openalex.org/C62913178","wikidata":"https://www.wikidata.org/wiki/Q7554361","display_name":"Software security assurance","level":4,"score":0.70546293},{"id":"https://openalex.org/C51234621","wikidata":"https://www.wikidata.org/wiki/Q2149495","display_name":"Testability","level":2,"score":0.63034165},{"id":"https://openalex.org/C172776598","wikidata":"https://www.wikidata.org/wiki/Q7943570","display_name":"Vulnerability management","level":4,"score":0.5507721},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5226807},{"id":"https://openalex.org/C148027188","wikidata":"https://www.wikidata.org/wiki/Q907375","display_name":"Unit testing","level":3,"score":0.47757107},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.42630038},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.38110957},{"id":"https://openalex.org/C184842701","wikidata":"https://www.wikidata.org/wiki/Q370563","display_name":"Cloud computing security","level":3,"score":0.26076198},{"id":"https://openalex.org/C103377522","wikidata":"https://www.wikidata.org/wiki/Q3493999","display_name":"Security information and event management","level":4,"score":0.23791331},{"id":"https://openalex.org/C29983905","wikidata":"https://www.wikidata.org/wiki/Q7445066","display_name":"Security service","level":3,"score":0.23481199},{"id":"https://openalex.org/C200601418","wikidata":"https://www.wikidata.org/wiki/Q2193887","display_name":"Reliability engineering","level":1,"score":0.20193738},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.20186499},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.1626279},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.12343377},{"id":"https://openalex.org/C167063184","wikidata":"https://www.wikidata.org/wiki/Q1400839","display_name":"Vulnerability assessment","level":3,"score":0.12078035},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.0},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.0},{"id":"https://openalex.org/C137176749","wikidata":"https://www.wikidata.org/wiki/Q4105337","display_name":"Psychological resilience","level":2,"score":0.0},{"id":"https://openalex.org/C542102704","wikidata":"https://www.wikidata.org/wiki/Q183257","display_name":"Psychotherapist","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/achi.2009.18","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, justice, and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.53}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":13,"referenced_works":["https://openalex.org/W1498728415","https://openalex.org/W1509088122","https://openalex.org/W1514888816","https://openalex.org/W1531064568","https://openalex.org/W1559498407","https://openalex.org/W2049864245","https://openalex.org/W2105160575","https://openalex.org/W2150898695","https://openalex.org/W2151488409","https://openalex.org/W2342091124","https://openalex.org/W3144627111","https://openalex.org/W4239720002","https://openalex.org/W4285719527"],"related_works":["https://openalex.org/W658105165","https://openalex.org/W4313400739","https://openalex.org/W2560421591","https://openalex.org/W2392503306","https://openalex.org/W2297344328","https://openalex.org/W2152250926","https://openalex.org/W2102558121","https://openalex.org/W2088401352","https://openalex.org/W2062583373","https://openalex.org/W125279808"],"abstract_inverted_index":{"Modern":[0],"software":[1,37,53,102],"systems":[2],"are":[3,26,48],"difficult":[4,106],"to":[5,8,30,33,81,88,98,110,118,123],"test":[6],"due":[7,29],"their":[9],"distributed":[10],"nature,":[11],"and":[12,78,91,107,129],"increased":[13],"security":[14,24,46,66,76,139],"complicates":[15],"testing":[16,35,105],"even":[17],"further.":[18],"Our":[19],"hypothesis":[20],"is":[21,54,57],"that":[22,36,61,103],"some":[23],"vulnerabilities":[25,47,77,97,140],"actually":[27],"introduced":[28],"developerspsila":[31],"need":[32,80,117],"facilitate":[34,89],"requirements":[38],"have":[39],"been":[40],"implemented":[41],"correctly.":[42],"If":[43],"these":[44],"temporary":[45],"not":[49],"removed":[50],"before":[51],"the":[52,72,83,101,116,131,136],"delivered,":[55],"there":[56],"a":[58,124,142],"great":[59],"risk":[60],"they":[62],"may":[63,121],"become":[64],"fielded":[65],"vulnerabilities.In":[67],"this":[68],"paper,":[69],"we":[70],"study":[71],"relationship":[73],"between":[74],"such":[75],"developers'":[79],"improve":[82],"testability":[84,111,120,146],"of":[85,100,126,133,138,144],"an":[86],"application":[87],"unit":[90],"integration":[92],"testing.":[93],"We":[94,113],"trace":[95],"detected":[96],"characteristics":[99],"made":[104],"therefore":[108],"led":[109],"improvements.":[112],"discuss":[114],"how":[115],"increase":[119],"relate":[122],"form":[125],"developer":[127],"usability,":[128],"what":[130],"ways":[132],"dealing":[134],"with":[135],"problem":[137],"as":[141],"consequence":[143],"increasing":[145],"are.":[147]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W2170847850","counts_by_year":[{"year":2021,"cited_by_count":1},{"year":2012,"cited_by_count":1}],"updated_date":"2024-12-10T13:37:08.057631","created_date":"2016-06-24"}