Risk-Aware Prioritization of Data Clumps Refactoring in Industrial Automation
Padma Iyenghar, Nils Baumgartner, Elke Pulvermueller · 2025
Industrial Automation and Control Systems (IACS) increasingly face security challenges. While refactoring enhances code maintainability, improper restructuring in custom IACS software can introduce new vulnerabilities. Applied without security awareness, refactoring may weaken access controls, aggregate sensitive data, or disrupt validation mechanisms, expanding the attack surface. This work presents a risk-based prioritization methodology for refactoring data clumps, integrating security factors such as Data Sensitivity (DS), Input Validation Inconsistency (IVI), and Access Control Inconsistency (ACI) alongside traditional maintainability metrics in a structured, quantifiable approach to security-aware refactoring. Empirical validation on five open-source projects reveals that security-sensitive functions are 63% more likely to exhibit long parameter names (LN) and high numbers of parameters (NP), highlighting a strong correlation between code complexity and security risk. This study provides actionable insights for identifying high-risk code structures and mitigating vulnerabilities through security-focused refactoring, forming the foundation for risk-informed strategies in large-scale IACS software.