SBIR-STTR Award

Analyzing Human Dimensions of Software Engineering Processes
Award last edited on: 12/31/2019

Sponsored Program
SBIR
Awarding Agency
DOD : DARPA
Total Award Amount
$1,499,994
Award Phase
2
Solicitation Topic Code
SB172-007
Principal Investigator
Anita D'Amico

Company Information

Applied Visions Inc (AKA: AVI)

6 Bayview Avenue
Northport, NY 11768
   (631) 759-3987
   info2@avi.com
   www.avi.com
Location: Multiple
Congr. District: 01
County: Suffolk

Phase I

Contract Number: N/A
Start Date: 00/00/00    Completed: 00/00/00
Phase I year
2019
Phase I Amount
$1
The Secure Decisions team will conduct research to: 1) determine how human dimensions of software engineering (SE) processes influence software security and quality; and 2) develop mechanisms for measuring these relationships in both open source and closed (private) development environments. The human dimensions of interest are: characteristics and behaviors of developers and development teams; environmental conditions that affect developers; and the chain of human activities that contribute to the introduction and persistence of vulnerabilities within a software repository. Software security is the primary outcome of interest; quality issues that influence an applications security are also studied. Two types of analyses will be performed on software developed under both open and closed environments: retrospective analyses of existing software repositories to find relationships between human dimensions and software security; and root cause analyses of vulnerabilities in which we will build a timeline of the chain of SE activities that led to the vulnerabilities introduction, persistence, eventual discovery, and remediation. A third type, concurrent analysis, will assess how human dimensions relate to software security using data collected while software is developed in closed environments. Results will be transitioned into commercial services, an open source curated database of vulnerability histories, and other research.

Phase II

Contract Number: 140D6319C0018
Start Date: 00/00/00    Completed: 00/00/00
Phase II year
2019
Phase II Amount
$1,499,993
The Secure Decisions team will conduct research to: 1) determine how human dimensions of software engineering (SE) processes influence software security and quality; and 2) develop mechanisms for measuring these relationships in both open source and closed (private) development environments. The human dimensions of interest are: characteristics and behaviors of developers and development teams; environmental conditions that affect developers; and the chain of human activities that contribute to the introduction and persistence of vulnerabilities within a software repository. Software security is the primary outcome of interest; quality issues that influence an applications security are also studied. Two types of analyses will be performed on software developed under both open and closed environments: retrospective analyses of existing software repositories to find relationships between human dimensions and software security; and root cause analyses of vulnerabilities in which we will build a timeline of the chain of SE activities that led to the vulnerabilities introduction, persistence, eventual discovery, and remediation. A third type, concurrent analysis, will assess how human dimensions relate to software security using data collected while software is developed in closed environments. Results will be transitioned into commercial services, an open source curated database of vulnerability histories, and other research.