SCW Icons
hero bg no divider
Blog

复制/粘贴是一种危险的编码技术

Pieter Danhieux
Published Sep 30, 2017
Last updated on Mar 10, 2026

Researchers from VirginiaTech released a paper after analysing hundreds of posts on the most popular developer forum (Stack Overflow). They looked at the type of questions asked around security, the most popular answers given by the community and the effect it has on code software engineers.

Not a real surprise for people who have been in Cyber Security for a while, but more awareness is needed around this problem from a developer perspective:

  • Security features provided by coding frameworks (e.g. JAVA Spring) are overly complicated and poorly documented
  • A substantial number of developers do not appear to understand the security implications of coding options, showing a lack of cyber security training
  • Many of the suggestions and "fixes" on these forums are not secure but were getting positives votes and thus higher in ratings

The report suggests the following solutions:

  • Workforce retraining
  • Semi-Automating security bug detection and fixing

We need to make security easy for developers and built-in from the start in order to maintain the speed in which businesses operate today.

"The significance of this work is that we provided empirical evidence for a significant number of alarming secure coding issues, which have not been previously reported," the paper says. "These issues are due to a variety of reasons, including the rapidly increasing need for enterprise security applications, the lack of security training in the software development workforce, and poorly designed security libraries."

https://www.theregister.com/2017/09/29/java_security_plagued_stack_overflow/

查看资源
查看资源

这项工作的意义在于,我们为大量令人震惊的安全编码问题提供了经验证据,这些问题以前从未报告过

对更多感兴趣?

Chief Executive Officer, Chairman, and Co-Founder

learn more

Secure Code Warrior可以帮助您的组织在整个软件开发生命周期中保护代码,并营造一种将网络安全放在首位的文化。无论您是 AppSec 经理、开发人员、首席信息安全官还是任何与安全相关的人,我们都可以帮助您的组织降低与不安全代码相关的风险。

预订演示
分享到:
linkedin brandsSocialx logo
作者
Pieter Danhieux
Published Sep 30, 2017

Chief Executive Officer, Chairman, and Co-Founder

Pieter Danhieux is a globally recognized security expert, with over 12 years experience as a security consultant and 8 years as a Principal Instructor for SANS teaching offensive techniques on how to target and assess organizations, systems and individuals for security weaknesses. In 2016, he was recognized as one of the Coolest Tech people in Australia (Business Insider), awarded Cyber Security Professional of the Year (AISA - Australian Information Security Association) and holds GSE, CISSP, GCIH, GCFA, GSEC, GPEN, GWAPT, GCIA certifications.

分享到:
linkedin brandsSocialx logo

Researchers from VirginiaTech released a paper after analysing hundreds of posts on the most popular developer forum (Stack Overflow). They looked at the type of questions asked around security, the most popular answers given by the community and the effect it has on code software engineers.

Not a real surprise for people who have been in Cyber Security for a while, but more awareness is needed around this problem from a developer perspective:

  • Security features provided by coding frameworks (e.g. JAVA Spring) are overly complicated and poorly documented
  • A substantial number of developers do not appear to understand the security implications of coding options, showing a lack of cyber security training
  • Many of the suggestions and "fixes" on these forums are not secure but were getting positives votes and thus higher in ratings

The report suggests the following solutions:

  • Workforce retraining
  • Semi-Automating security bug detection and fixing

We need to make security easy for developers and built-in from the start in order to maintain the speed in which businesses operate today.

"The significance of this work is that we provided empirical evidence for a significant number of alarming secure coding issues, which have not been previously reported," the paper says. "These issues are due to a variety of reasons, including the rapidly increasing need for enterprise security applications, the lack of security training in the software development workforce, and poorly designed security libraries."

https://www.theregister.com/2017/09/29/java_security_plagued_stack_overflow/

查看资源
查看资源

填写下面的表格下载报告

我们希望获得您的许可,以便向您发送有关我们的产品和/或相关安全编码主题的信息。我们将始终非常谨慎地对待您的个人信息,绝不会出于营销目的将其出售给其他公司。

提交
scw success icon
scw error icon
要提交表单,请启用 “分析” Cookie。完成后,可以随意再次禁用它们。

Researchers from VirginiaTech released a paper after analysing hundreds of posts on the most popular developer forum (Stack Overflow). They looked at the type of questions asked around security, the most popular answers given by the community and the effect it has on code software engineers.

Not a real surprise for people who have been in Cyber Security for a while, but more awareness is needed around this problem from a developer perspective:

  • Security features provided by coding frameworks (e.g. JAVA Spring) are overly complicated and poorly documented
  • A substantial number of developers do not appear to understand the security implications of coding options, showing a lack of cyber security training
  • Many of the suggestions and "fixes" on these forums are not secure but were getting positives votes and thus higher in ratings

The report suggests the following solutions:

  • Workforce retraining
  • Semi-Automating security bug detection and fixing

We need to make security easy for developers and built-in from the start in order to maintain the speed in which businesses operate today.

"The significance of this work is that we provided empirical evidence for a significant number of alarming secure coding issues, which have not been previously reported," the paper says. "These issues are due to a variety of reasons, including the rapidly increasing need for enterprise security applications, the lack of security training in the software development workforce, and poorly designed security libraries."

https://www.theregister.com/2017/09/29/java_security_plagued_stack_overflow/

观看网络研讨会
开始吧
learn more

点击下面的链接并下载此资源的PDF。

Secure Code Warrior可以帮助您的组织在整个软件开发生命周期中保护代码,并营造一种将网络安全放在首位的文化。无论您是 AppSec 经理、开发人员、首席信息安全官还是任何与安全相关的人,我们都可以帮助您的组织降低与不安全代码相关的风险。

查看报告预订演示
查看资源
分享到:
linkedin brandsSocialx logo
对更多感兴趣?

分享到:
linkedin brandsSocialx logo
作者
Pieter Danhieux
Published Sep 30, 2017

Chief Executive Officer, Chairman, and Co-Founder

Pieter Danhieux is a globally recognized security expert, with over 12 years experience as a security consultant and 8 years as a Principal Instructor for SANS teaching offensive techniques on how to target and assess organizations, systems and individuals for security weaknesses. In 2016, he was recognized as one of the Coolest Tech people in Australia (Business Insider), awarded Cyber Security Professional of the Year (AISA - Australian Information Security Association) and holds GSE, CISSP, GCIH, GCFA, GSEC, GPEN, GWAPT, GCIA certifications.

分享到:
linkedin brandsSocialx logo

Researchers from VirginiaTech released a paper after analysing hundreds of posts on the most popular developer forum (Stack Overflow). They looked at the type of questions asked around security, the most popular answers given by the community and the effect it has on code software engineers.

Not a real surprise for people who have been in Cyber Security for a while, but more awareness is needed around this problem from a developer perspective:

  • Security features provided by coding frameworks (e.g. JAVA Spring) are overly complicated and poorly documented
  • A substantial number of developers do not appear to understand the security implications of coding options, showing a lack of cyber security training
  • Many of the suggestions and "fixes" on these forums are not secure but were getting positives votes and thus higher in ratings

The report suggests the following solutions:

  • Workforce retraining
  • Semi-Automating security bug detection and fixing

We need to make security easy for developers and built-in from the start in order to maintain the speed in which businesses operate today.

"The significance of this work is that we provided empirical evidence for a significant number of alarming secure coding issues, which have not been previously reported," the paper says. "These issues are due to a variety of reasons, including the rapidly increasing need for enterprise security applications, the lack of security training in the software development workforce, and poorly designed security libraries."

https://www.theregister.com/2017/09/29/java_security_plagued_stack_overflow/

目录

下载PDF
查看资源
对更多感兴趣?

Chief Executive Officer, Chairman, and Co-Founder

learn more

Secure Code Warrior可以帮助您的组织在整个软件开发生命周期中保护代码,并营造一种将网络安全放在首位的文化。无论您是 AppSec 经理、开发人员、首席信息安全官还是任何与安全相关的人,我们都可以帮助您的组织降低与不安全代码相关的风险。

预订演示下载
分享到:
linkedin brandsSocialx logo
资源中心

帮助您入门的资源

更多帖子
资源中心

帮助您入门的资源

更多帖子