Software Security Analysis in 2030 and Beyond: A Research Roadmap
M. Böhme, E. Bodden, T. Bultan, C. Cadar, Y. Liu, G. Scanniello, ACM Transactions on Software Engineering and Methodology (2024).
Download
No fulltext has been uploaded.
DOI
Journal Article
| Published
| English
Author
Böhme, Marcel;
Bodden, EricLibreCat
;
Bultan, Tevfik;
Cadar, Cristian;
Liu, Yang;
Scanniello, Giuseppe

Abstract
<jats:p>As our lives, our businesses, and indeed our world economy become increasingly reliant on the secure operation of many interconnected software systems, the software engineering research community is faced with unprecedented research challenges, but also with exciting new opportunities. In this roadmap paper, we outline our vision of Software Security Analysis for the systems of the future. Given the recent advances in generative AI, we need new methods to assess and maximize the security of code co-written by machines. As our systems become increasingly heterogeneous, we need practical approaches that work even if some functions are automatically generated, e.g., by deep neural networks. As software systems depend evermore on the software supply chain, we need tools that scale to an entire ecosystem. What kind of vulnerabilities exist in future systems and how do we detect them? When all the shallow bugs are found, how do we discover vulnerabilities hidden deeply in the system? Assuming we cannot find all security flaws, how can we nevertheless protect our system? To answer these questions, we start our roadmap with a survey of recent advances in software security, then discuss open challenges and opportunities, and conclude with a long-term perspective for the field.</jats:p>
Publishing Year
Journal Title
ACM Transactions on Software Engineering and Methodology
LibreCat-ID
Cite this
Böhme M, Bodden E, Bultan T, Cadar C, Liu Y, Scanniello G. Software Security Analysis in 2030 and Beyond: A Research Roadmap. ACM Transactions on Software Engineering and Methodology. Published online 2024. doi:10.1145/3708533
Böhme, M., Bodden, E., Bultan, T., Cadar, C., Liu, Y., & Scanniello, G. (2024). Software Security Analysis in 2030 and Beyond: A Research Roadmap. ACM Transactions on Software Engineering and Methodology. https://doi.org/10.1145/3708533
@article{Böhme_Bodden_Bultan_Cadar_Liu_Scanniello_2024, title={Software Security Analysis in 2030 and Beyond: A Research Roadmap}, DOI={10.1145/3708533}, journal={ACM Transactions on Software Engineering and Methodology}, publisher={Association for Computing Machinery (ACM)}, author={Böhme, Marcel and Bodden, Eric and Bultan, Tevfik and Cadar, Cristian and Liu, Yang and Scanniello, Giuseppe}, year={2024} }
Böhme, Marcel, Eric Bodden, Tevfik Bultan, Cristian Cadar, Yang Liu, and Giuseppe Scanniello. “Software Security Analysis in 2030 and Beyond: A Research Roadmap.” ACM Transactions on Software Engineering and Methodology, 2024. https://doi.org/10.1145/3708533.
M. Böhme, E. Bodden, T. Bultan, C. Cadar, Y. Liu, and G. Scanniello, “Software Security Analysis in 2030 and Beyond: A Research Roadmap,” ACM Transactions on Software Engineering and Methodology, 2024, doi: 10.1145/3708533.
Böhme, Marcel, et al. “Software Security Analysis in 2030 and Beyond: A Research Roadmap.” ACM Transactions on Software Engineering and Methodology, Association for Computing Machinery (ACM), 2024, doi:10.1145/3708533.