As security becomes more relevant for many companies, the popularity of static program analysis (SPA) tools is increasing. In this paper, we target the use of SPA tools among companies in Germany with a focus on security. We give insights on the current issues and the developers' willingness to configure the tools to overcome these issues. Compared to previous studies, our study considers the companies' culture and processes for using SPA tools. We conducted an online survey with 256 responses and semi-structured interviews with 17 product owners and executives from multiple companies. Our results show a diversity in the usage of tools. Only half of our survey participants use SPA tools. The free tools tend to be more popular among software developers. In most companies, software developers are encouraged to use free tools, whereas commercial tools can be requested. However, the product owners and executives in our interviews reported that their developers do not request new tools. We also find out that automatic security checks with tools are rarely performed on each release.
翻译:随着安全对许多公司越来越重要,静态程序分析工具的普及程度正在增加。在本文中,我们的目标是德国公司使用静态程序分析工具,重点是安全。我们深入了解当前问题,以及开发商是否愿意配置工具来克服这些问题。与以往的研究相比,我们的研究考虑了公司使用安全分析工具的文化和程序。我们进行了在线调查,共收到256份答复,并与多个公司17名产品所有者和管理人员进行了半结构性访谈。我们的结果显示工具使用的多样性。只有一半的调查参与者使用安全分析工具。免费工具往往在软件开发商中更为普及。在大多数公司中,鼓励软件开发商使用免费工具,而商业工具则可以请求使用。然而,我们访谈中的产品所有者和管理人员报告说,他们的开发商并不要求新的工具。我们还发现,每次发布工具时很少进行自动安全检查。