Software Security Analysis in 2030 and Beyond: A Research Roadmap


연구 분야: Strategies



학회: ACM Transactions on Software Engineering and Methodology, Volume 34, Issue 5


초록

As our lives, our businesses, and indeed our world economy become increasingly reliant on the secure operation of many interconnected software systems, the software engineering research community is faced with unprecedented research challenges, but also with exciting new opportunities. In this roadmap article, we outline our vision of software security analysis for the systems of the future. Given the recent advances in generative AI, we need new methods to assess and maximize the security of code co-written by machines. As our systems become increasingly heterogeneous, we need practical approaches that work even if some functions are automatically generated, e.g., by deep neural networks. As software systems depend evermore on the software supply chain, we need tools that scale to an entire ecosystem. What kind of vulnerabilities exist in future systems and how do we detect them? When all the shallow bugs are found, how do we discover vulnerabilities hidden deeply in the system? Assuming we cannot find all security flaws, how can we nevertheless protect our system? To answer these questions, we start our roadmap with a survey of recent advances in software security, then discuss open challenges and opportunities, and conclude with a long-term perspective for the field.


Author Profile
Yang Liu

Nanyang Technological University Singapore Singapore

Singapore
Author Profile
Marcel Böhme

Max Planck Institute for Security and Privacy Bochum Germany

Andorra
Author Profile
Eric Bodden

Faculty of Electrical Engineering Computer Science and Mathematics Department of Computer Science Software Engineering Group Paderborn University Paderborn Germany

Andorra

📄 논문 정보

발행 연도 2025년
인용수 2
출판 국가 Singapore, Italy, Andorra, Austria
사이트 ACM
좋아요 수 0

연관 논문 목록 (292건)