Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Empowering Software Engineers to Design More Secure Web Applications: Guidelines and Potential of Using LLMs as a Recommender Tool
Department of Computer Science and Engineering, Chalmers University of Technology, Gothenburg, Västra Götaland, Sweden.
Department of Computer Science and Engineering, Chalmers University of Technology, Gothenburg, Västra Götaland, Sweden.
Department of Computer Science and Engineering, Chalmers University of Technology, Gothenburg, Västra Götaland, Sweden.
Department of Computer Science and Engineering, Chalmers University of Technology, Gothenburg, Västra Götaland, Sweden.
Show others and affiliations
2026 (English)In: Journal of Software: Evolution and Process, Vol. 38, no 2Article in journal (Refereed) Published
Abstract [en]

As software applications get increasingly connected and complex, cybersecurity becomes more and more important to consider during development and evaluation. Software engineers need to be aware of various security threats and the countermeasures that can be taken to mitigate them. Currently, there is a lack of guidance for software engineers aiming to develop secure web applications. We conducted a design science research study, resulting in a set of guidelines to aid software engineers in developing secure web applications. The set of guidelines was constructed based on interview data with 10 industry practitioners. These guidelines were then evaluated using a survey with 28 respondents. Additionally, we conducted experiments in which we provided a large language model with our guidelines and vulnerability reports as input. The large language model should extend the given vulnerability reports by recommending which of our guidelines can help prevent the given vulnerability in the future. The extended reports were evaluated by two external researchers experienced in cyber security and one author. Our results indicate that developers consider using these proposed guidelines for the development and assessment of secure web applications in different stages of the software development lifecycle. Our results also show that it is possible to automatically enhance vulnerability reports to support developers meaningfully and that the guidelines recommended by the large language model are useful to prevent the respective vulnerabilities in the future

Place, publisher, year, edition, pages
John Wiley & Sons, 2026. Vol. 38, no 2
Keywords [en]
cybersecurity, design science research, experiments, guidelines, interviews, LLM, software engineering, survey, web applications
National Category
Software Engineering
Identifiers
URN: urn:nbn:se:ri:diva-80898DOI: 10.1002/smr.70083Scopus ID: 2-s2.0-105029755627OAI: oai:DiVA.org:ri-80898DiVA, id: diva2:2043763
Note

QC 20260306

Available from: 2026-03-06 Created: 2026-03-06 Last updated: 2026-03-06Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full textScopus

Authority records

Mohamad, Mazen

Search in DiVA

By author/editor
Mohamad, Mazen
By organisation
Electrification and Reliability
Software Engineering

Search outside of DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 23 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf