Abstract
Research efforts tried to expose students to security topics early in the undergraduate CS curriculum. However, such efforts are rarely adopted in practice and remain less effective when it comes to writing secure code. In our prior work [18], we identified key issues with the how students code and grouped them into six themes: (a) Knowledge of C, (b) Understanding compiler and OS messages, (c) Utilization of resources, (d) Knowledge of memory, (e) Awareness of unsafe functions, and (f) Understanding of security topics. In this work, we aim to understand students' knowledge about each theme and how that knowledge affects their secure coding practices. Thus, we propose a modified SOLO taxonomy for the latter five themes. We apply the taxonomy to the coding interview data of 21 students from two US R1 universities. Our results suggest that most students have limited knowledge of each theme. We also show that scoring low in these themes correlates with why students fail to write secure code and identify possible vulnerabilities.
Author supplied keywords
Cite
CITATION STYLE
Almansoori, M., Lam, J., Fang, E., Soosai Raj, A. G., & Chatterjee, R. (2023). Towards Finding the Missing Pieces to Teach Secure Programming Skills to Students. In SIGCSE 2023 - Proceedings of the 54th ACM Technical Symposium on Computer Science Education (Vol. 1, pp. 973–979). Association for Computing Machinery, Inc. https://doi.org/10.1145/3545945.3569730
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.