← Research using Delve

ESEC/FSE 2023: Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering · November 2023

Understanding Hackers’ Work: An Empirical Study of Offensive Security Practitioners

Andreas Happe, Jürgen Cito

Faculty of Informatics, TU Wien, Vienna

Reflexive thematic analysis HCI & computer science

How they used Delve

Software engineering researchers at TU Wien used Delve to run a reflexive thematic analysis of interviews with 12 professional penetration testers and red teamers, with both authors coding separately and reconciling their labels, to map how offensive security work is actually done.

“Scrubbed interviews were loaded into delve [5] for thematic analysis. Analysis. Reflexive Thematic Analysis [26] was chosen to perform a data-driven exploratory analysis of interview transcriptions.”

Field
Software engineering and IT security; how offensive security practitioners (penetration testers, red teamers) actually work
Data
Semi-structured interviews with 12 professional offensive-security practitioners with at least four years' experience, recruited by snowball sampling from security companies, security-challenge finalists and conference attendees across roughly Central Europe; transcripts were scrubbed of sensitive data and returned to interviewees for confirmation before analysis
Approach
Data-driven exploratory reflexive thematic analysis: familiarization, tagging extracts with codes, clustering codes into underlying themes, then reviewing, defining and naming them. Sampling continued to theoretical saturation - reached at the 12th interview - with a two-part stopping rule distinguishing common themes from specialty-area themes. All data was analysed separately by both authors and their labelling results compared, with ambiguities discussed and resolved
Data types
Interviews

Abstract

Offensive security-tests are commonly employed to pro-actively discover potential vulnerabilities. They are performed by specialists, also known as penetration-testers or white-hat hackers. The chronic lack of available white-hat hackers prevents sufficient security test coverage of software. Research into automation tries to alleviate this problem by improving the efficiency of security testing. To achieve this, researchers and tool builders need a solid understanding of how hackers work, their assumptions, and pain points.

Citation

Andreas Happe, Jürgen Cito (2023). Understanding Hackers’ Work: An Empirical Study of Offensive Security Practitioners. ESEC/FSE 2023: Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering. https://doi.org/10.1145/3611643.3613900

Resources

Start your 14 day free trial of Delve