Skip to main content

Showing 1–8 of 8 results for author: Lechner, U

  1. arXiv:2102.10436  [pdf, other

    cs.SE

    Raising Security Awareness using Cybersecurity Challenges in Embedded Programming Courses

    Authors: Tiago Espinha Gasiba, Samra Hodzic, Ulrike Lechner, Maria Pinto-Albuquerque

    Abstract: Security bugs are errors in code that, when exploited, can lead to serious software vulnerabilities. These bugs could allow an attacker to take over an application and steal information. One of the ways to address this issue is by means of awareness training. The Sifu platform was developed in the industry, for the industry, with the aim to raise software developers' awareness of secure coding. Th… ▽ More

    Submitted 20 February, 2021; originally announced February 2021.

    Comments: Preprint accepted for publication at the First International Conference on Code Quality (ICCQ 2021)

  2. arXiv:2102.10432  [pdf, other

    cs.SE

    CyberSecurity Challenges: Serious Games for Awareness Training in Industrial Environments

    Authors: Tiago Espinha Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque

    Abstract: Awareness of cybersecurity topics, e.g., related to secure coding guidelines, enables software developers to write secure code. This awareness is vital in industrial environments for the products and services in critical infrastructures. In this work, we introduce and discuss a new serious game designed for software developers in the industry. This game addresses software developers' needs and is… ▽ More

    Submitted 20 February, 2021; originally announced February 2021.

    Comments: Preprint accepted for publication at the 17. Deutscher IT-Sicherheitskongress. arXiv admin note: substantial text overlap with arXiv:2102.05345

  3. arXiv:2102.10431  [pdf, ps, other

    cs.SE

    Raising Secure Coding Awareness for Software Developers in the Industry

    Authors: Tiago Espinha Gasiba, Ulrike Lechner

    Abstract: Many industrial IT security standards and policies mandate the usage of a secure coding methodology in the software development process. This implies two different aspects: first, secure coding must be based on a set of secure coding guidelines, and second software developers must be aware of these secure coding practices. On the one side, secure coding guidelines seems a bit like a black-art: whi… ▽ More

    Submitted 20 February, 2021; originally announced February 2021.

    Comments: Preprint accepted for publication at the 2019 IEEE 27th International Requirements Engineering Conference Workshops (REW)

  4. arXiv:2102.10430  [pdf, other

    cs.SE cs.CR

    Cybersecurity Awareness Platform with Virtual Coach and Automated Challenge Assessment

    Authors: Tiago Espinha Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque, Anmoal Porwal

    Abstract: Over the last years, the number of cyber-attacks on industrial control systems has been steadily increasing. Among several factors, proper software development plays a vital role in keeping these systems secure. To achieve secure software, developers need to be aware of secure coding guidelines and secure coding best practices. This work presents a platform geared towards software developers in th… ▽ More

    Submitted 20 February, 2021; originally announced February 2021.

    Comments: Preprint accepted for publication at the 6th Workshop On The Security Of Industrial Control Systems & Of Cyber-Physical Systems (CyberICPS 2020)

  5. arXiv:2102.05345  [pdf, other

    cs.SE

    CyberSecurity Challenges for Software Developer Awareness Training in Industrial Environments

    Authors: Tiago Espinha Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque

    Abstract: Awareness of cybersecurity topics facilitates software developers to produce secure code. This awareness is especially important in industrial environments for the products and services in critical infrastructures. In this work, we address how to raise awareness of software developers on the topic of secure coding. We propose the "CyberSecurity Challenges", a serious game designed to be used in an… ▽ More

    Submitted 10 February, 2021; originally announced February 2021.

    Comments: Preprint accepted for publication at the 16th International Conference on Wirtschaftsinformatik

  6. arXiv:2102.05343  [pdf, other

    cs.SE

    Is Secure Coding Education in the Industry Needed? An Investigation Through a Large Scale Survey

    Authors: Tiago Espinha Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque, Daniel Mendez

    Abstract: The Department of Homeland Security in the United States estimates that 90% of software vulnerabilities can be traced back to defects in design and software coding. The financial impact of these vulnerabilities has been shown to exceed 380 million USD in industrial control systems alone. Since software developers write software, they also introduce these vulnerabilities into the source code. Howev… ▽ More

    Submitted 10 February, 2021; originally announced February 2021.

    Comments: Preprint accepted for publication at the 43rd International Conference on Software Engineering

  7. arXiv:2101.02108  [pdf, other

    cs.SE

    Design of Secure Coding Challenges for Cybersecurity Education in the Industry

    Authors: Tiago Espinha Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque, Alae Zouitni

    Abstract: According to a recent survey with more than 4000 software developers, less than half of developers can spot security holes. As a result, software products present a low-security quality expressed by vulnerabilities that can be exploited by cyber-criminals. This lack of quality and security is particularly dangerous if the software which contains the vulnerabilities is deployed in critical infrastr… ▽ More

    Submitted 6 January, 2021; originally announced January 2021.

    Comments: Preprint accepted for publication at the 13th International Conference on the Quality of Information and Communications Technology

  8. arXiv:2101.02085  [pdf, other

    cs.SE

    Awareness of Secure Coding Guidelines in the Industry -- A first data analysis

    Authors: Tiago Espinha Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque, Daniel Mendez Fernandez

    Abstract: Software needs to be secure, in particular, when deployed to critical infrastructures. Secure coding guidelines capture practices in industrial software engineering to ensure the security of code. This study aims to assess the level of awareness of secure coding in industrial software engineering, the skills of software developers to spot weaknesses in software code, avoid them, and the organizati… ▽ More

    Submitted 6 January, 2021; originally announced January 2021.

    Comments: Preprint accepted for publication at The 19th IEEE International Conference on Trust, Security and Privacy in Computing and Communications (IEEE TrustCom 2020)