arrow
Return

Why Johnny can't develop a secure application? A usability analysis of Java Secure Socket Extension API

delete2019-01-01
delete11
PRE
AI
C
Chamila Wijayarathna *
N
Nalin Asanka Gamagedara Arachchilage
DOI:10.1016/j.cose.2018.09.007delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Lack of usability of security Application Programming Interfaces (APIs) is one of the main reasons for mistakes that programmers make that result in security vulnerabilities in software applications they develop. Especially, APIs that provide Transport Layer Security (TLS) related functionalities are sometimes too complex for programmers to learn and use. Therefore, applications are often diagnosed with vulnerable TLS implementations due to mistakes made by programmers. In this work, we evaluated the usability of Java Secure Socket Extension (JSSE) API to identify usability issues in it that persuade programmers to make mistakes while developing applications that would result in security vulnerabilities. We conducted a study with 11 programmers where each of them spent around 2 hours and attempted to develop a secure programming solution using JSSE API. From data we collected, we identified 59 usability issues that exist in JSSE API. Then we divided those usability issues into 15 cognitive dimensions and analyzed how those issues affected the experience of participant programmers. Results of our study provided useful insights about how TLS APIs and similar security APIs should be designed, developed and improved to provide a better experience for programmers who use them. (C) 2018 Elsevier Ltd. All rights reserved.
Keywords:
Security APIs
Transport Layer Security
Programmer experience
API usability
Java Secure Socket Extension
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

No organization information available