Engaging_Company_Developers_in_Security_Research_Studies__A_Comprehensive_Literature_Review_and_Quantitative_Survey_Replication_Package.pdf
收藏资源简介:
This is the supplementary material for the USENIX 2024 paper "Engaging Company Developers in Security Research Studies: A Comprehensive Literature Review and Quantitative Survey". The paper explores the challenges and strategies for engaging professional software developers in empirical security research. Through a literature review and a survey of 340 developers, the study identifies that while most developers prioritize security tasks and are willing to participate in security studies, they find these tasks more challenging despite having more experience. The research highlights the effectiveness of targeted emails, employer recommendations, and CS-related mailing lists as recruitment channels. It also provides guidelines on study length and compensation, emphasizing the importance of adequate compensation and transparency in reporting study parameters to improve participation rates. The authors suggest that Qualtrics could be a useful recruitment platform, despite some challenges, and call for further research to enhance recruitment practices.



