Investigating the relationship between developer collaboration and software security
Laurie A. Williams, Andrew Meneely · 2011
With each new developer to a software development team comes a greater challenge to manage the communication, coordination, and knowledge transfer amongst teammates. Lack of team cohesion, miscommunications, and misguided effort can lead to all kinds of problems, including security vulnerabilities. In this dissertation research, we focus on examining the statistical relationships between development team structure and security vulnerabilities. The statistical relationships demonstrated in this research provide us with (a) predictive models for finding security vulnerabilities in software prior to its release; and (b) insight into how effective software development teams are organized. This dissertation is comprised of three research projects surrounding what we call developer activity metrics. Mostly based on social network analysis, developer activity metrics are designed to quantify how groups of software developers are working with each other. Developer activity data come from software development artifacts that provide information such as version control change logs and issue tracking systems. The developer activity data is transformed into a developer network designed to represent the sociotechnical organization of labor in a team, specifically “who is working with whom” within the scope of a given development project. The three research projects are as follows: Security Correlation Study. We applied social network analysis techniques to three open source software products, and discovered a consistent statistical association between metrics measuring developer activity and post-release security vulnerabilities. · Perception Corroboration Study. We surveyed developers from the same three open source projects and found that developersi¦ perceptions of collaboration and expertise corroborate evidence of collaboration and expertise in developer activity metrics. · Synthesis Study. We gathered the results from the related work both inside software engineering and in the field of socio-technical research in general. We synthesized our results into a single paradigm with conjectures for socio-technical research in software engineering. These three research project have resulted in the following findings: · Source code files changed by many developers (in our case studies, 6 developers or more) are more likely to have at least one post-release security vulnerability. · Vulnerability prediction models based on developer activity metrics can be used across different software development projects. · If two developers change the same source code within the same month, they typically perceive they are collaborating with each other. · The degree of separation between two developers in a developer network typically represents their perceived socio-technical distance. Having a high centrality in a developer network is associated with being reputed as being a project expert.