Understanding Hackers’ Work: An Empirical Study of Offensive Security Practitioners
Faculty of Informatics, TU Wien, Vienna
How they used Delve
Software engineering researchers at TU Wien used Delve to run a reflexive thematic analysis of interviews with 12 professional penetration testers and red teamers, with both authors coding separately and reconciling their labels, to map how offensive security work is actually done.
“Scrubbed interviews were loaded into delve [5] for thematic analysis. Analysis. Reflexive Thematic Analysis [26] was chosen to perform a data-driven exploratory analysis of interview transcriptions.”
- Field
- Software engineering and IT security; how offensive security practitioners (penetration testers, red teamers) actually work
- Data
- Semi-structured interviews with 12 professional offensive-security practitioners with at least four years' experience, recruited by snowball sampling from security companies, security-challenge finalists and conference attendees across roughly Central Europe; transcripts were scrubbed of sensitive data and returned to interviewees for confirmation before analysis
- Approach
- Data-driven exploratory reflexive thematic analysis: familiarization, tagging extracts with codes, clustering codes into underlying themes, then reviewing, defining and naming them. Sampling continued to theoretical saturation - reached at the 12th interview - with a two-part stopping rule distinguishing common themes from specialty-area themes. All data was analysed separately by both authors and their labelling results compared, with ambiguities discussed and resolved
- Data types
- Interviews
Abstract
Offensive security-tests are commonly employed to pro-actively discover potential vulnerabilities. They are performed by specialists, also known as penetration-testers or white-hat hackers. The chronic lack of available white-hat hackers prevents sufficient security test coverage of software. Research into automation tries to alleviate this problem by improving the efficiency of security testing. To achieve this, researchers and tool builders need a solid understanding of how hackers work, their assumptions, and pain points.
Citation
Andreas Happe, Jürgen Cito (2023). Understanding Hackers’ Work: An Empirical Study of Offensive Security Practitioners. ESEC/FSE 2023: Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering. https://doi.org/10.1145/3611643.3613900