arrow
Return

How Does Refactoring Impact Security When Improving Quality? A Security-Aware Refactoring Approach

delete2020-01-01
delete5
PRE
AI
C
Chaima Abid
M
Marouane Kessentini *
V
Vahid Alizadeh
M
Mouna Dhouadi
R
Rick Kazman
DOI:10.1109/TSE.2020.3005995delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
While state of the art of software refactoring research uses various quality attributes to identify refactoring opportunities and evaluate refactoring recommendations, the impact of refactoring on the security of software systems when improving other quality objectives is under-explored. It is critical to understand how a system is resistant to security risks after refactoring to improve quality metrics. For instance, refactoring is widely used to improve the reusability of code, however such an improvement may increase the attack surface due to the created abstractions. Increasing the spread of security-critical classes in the design to improve modularity may result in reducing the resilience of software systems to attacks. In this paper, we investigated the possible impact of improving different quality attributes (e.g., reusability, extendibility, etc.), from the QMOOD model, effectiveness on a set of 8 security metrics defined in the literature related to the data access. We also studied the impact of different refactorings on these static security metrics. Then, we proposed a multi-objective refactoring recommendation approach to find a balance between quality attributes and security based on the correlation results to guide the search. We evaluated our tool on 30 open source projects. We also collected the practitioner perceptions on the refactorings recommended by our tool in terms of the possible impact on both security and other quality attributes. Our results confirm that developers need to make trade-offs between security and other qualities when refactoring software systems due to the negative correlations between them.
Keywords:
Security
Measurement
Tools
Correlation
Software systems
Computer bugs
Quality
critical code
security metrics
attack surface
refactoring
multi-objective search
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Transactions on Software Engineering cover
IEEE Transactions on Software Engineering
IF:
5.6
Papers:
2.8K
Citations:
1.1W

Organization

U
University of Michigan
Scholars:
6.4W
Papers: 5.3W
Citations: 124
U
university of michigan system
Scholars:
9.1W
Papers: 8.6W
Citations: 133