Exportar Publicação

A publicação pode ser exportada nos seguintes formatos: referência da APA (American Psychological Association), referência do IEEE (Institute of Electrical and Electronics Engineers), BibTeX e RIS.

Exportar Referência (APA)
Iosif, A., Lechner, U., Pinto-Albuquerque, M. & Gasiba, T. (2024). Code review for cybersecurity in the industry: Insights from gameplay analytics. In André L. Santos, Maria Pinto-Albuquerque (Ed.), 5th International Computer Programming Education Conference (ICPEC 2024). Lisboa: Schloss Dagstuhl.
Exportar Referência (IEEE)
I. Andrei-Cristian et al.,  "Code review for cybersecurity in the industry: Insights from gameplay analytics", in 5th Int. Computer Programming Education Conf. (ICPEC 2024), André L. Santos, Maria Pinto-Albuquerque, Ed., Lisboa, Schloss Dagstuhl, 2024, vol. 122
Exportar BibTeX
@inproceedings{andrei-cristian2024_1785942902312,
	author = "Iosif, A. and Lechner, U. and Pinto-Albuquerque, M. and Gasiba, T.",
	title = "Code review for cybersecurity in the industry: Insights from gameplay analytics",
	booktitle = "5th International Computer Programming Education Conference (ICPEC 2024)",
	year = "2024",
	editor = "André L. Santos, Maria Pinto-Albuquerque",
	volume = "122",
	number = "",
	series = "",
	doi = "10.4230/OASIcs.ICPEC.2024.14",
	publisher = "Schloss Dagstuhl",
	address = "Lisboa",
	organization = "",
	url = "https://www.icpeconf.org/"
}
Exportar RIS
TY  - CPAPER
TI  - Code review for cybersecurity in the industry: Insights from gameplay analytics
T2  - 5th International Computer Programming Education Conference (ICPEC 2024)
VL  - 122
AU  - Iosif, A.
AU  - Lechner, U.
AU  - Pinto-Albuquerque, M.
AU  - Gasiba, T.
PY  - 2024
SN  - 2190-6807
DO  - 10.4230/OASIcs.ICPEC.2024.14
CY  - Lisboa
UR  - https://www.icpeconf.org/
AB  - In pursuing a secure software development lifecycle, industrial developers employ a combination of automated and manual techniques to mitigate vulnerabilities in source code. Among manual techniques, code review is a promising approach, with growing interest within the industry around it. However, the effectiveness of code reviews for security purposes relies on developers' empowerment and awareness, particularly in the domain-specific knowledge required for identifying security issues. Our study explores the use of DuckDebugger, a serious game designed specifically to enhance industrial practitioners' security knowledge for code reviews. By exploring analytics data collected from game interactions, we provide insights into player behavior and explore how the game influences their approach to security-focused code reviews. Altogether, we explore data from 13 events conducted in the industry together with 224 practitioners, and derive metrics such as the time it takes participants spend to reviewing a line of code and the time required to compose a comment. We offer empirical indicators on how serious games may effectively be utilized to empower developers, propose potential design improvements for educational tools, and discuss broader implications for the use of Serious Games in industrial settings. Furthermore, our discussion extends to include a discussion outlining the next steps for our work, together with possible limitations. 
ER  -