We need solutions that work in both theory and practice. However, as truth is stranger than fiction, this means that to attain this grand goal we cannot simply retreat to our study but will need to draw insight from empirical data. That is, unless a tool is easy to use properly, although it may be secure in theory, it can still prove a liability in practice – which goes for both end-users and developers.
In short, this research area aims to devise an engineering process that significantly improves the security and privacy of today's real-world software, that keep pace with the continuing growth in complexity for future IT systems, and that is conveniently usable even by laypeople users and developers. It provides techniques for ensuring the security of web applications and services as well as usable and effective solutions for application development and maintenance.
USENIX-Security
31st USENIX Security Symposium31st USENIX Security Symposium
SP
43rd IEEE Symposium on Security and Privacy (S&P '22)
SP
IEEE Symposium on Security & Privacy43rd IEEE Symposium on Security and Privacy
WWW
TheWebConf 2022TheWebConf 2022
ACM Transactions on Computer-Human Interaction