10th IEEE High Assurance Systems Engineering Symposium (HASE'07) 2007
DOI: 10.1109/hase.2007.55
|View full text |Cite
|
Sign up to set email alerts
|

Vulnerability Discovery in Multi-Version Software Systems

Abstract: -The vulnerability discovery process for a program describes the rate at which the security vulnerabilities are discovered. Being able to predict the vulnerability discovery process allows developers to adequately plan for resource allocation needed to develop patches for them. It also enables the users to assess the security risks. Thus there is a need to develop a model of the discovery process that can predict the number of vulnerabilities that are likely to be discovered in a given time frame. Recent studi… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
16
0

Year Published

2013
2013
2021
2021

Publication Types

Select...
5
3
1

Relationship

1
8

Authors

Journals

citations
Cited by 29 publications
(17 citation statements)
references
References 10 publications
0
16
0
Order By: Relevance
“…A study on diversity across software versions is presented in . The authors propose a new discovery model that takes into account the software versions and therefore the importance of shared code on vulnerability discovery.…”
Section: Related Workmentioning
confidence: 99%
“…A study on diversity across software versions is presented in . The authors propose a new discovery model that takes into account the software versions and therefore the importance of shared code on vulnerability discovery.…”
Section: Related Workmentioning
confidence: 99%
“…Another approach for vulnerability assessment is Quantitative modeling of vulnerability discovery process based on shared source code measurements among multi-version software systems. Such a modeling approach can be used for assessing security risk both before and after the release of a version [17].…”
Section: Methodsmentioning
confidence: 99%
“…Their proposed AML model assumes a symmetrical shape around the peak discovery rate value [6]. A Weibull distribution-based VDM was proposed by Kim in 2007 [18]. Li et al [19] empirically showed that, in comparison to other reliability models, a Weibull model is better for defect occurrence across a wide range of software systems.…”
Section: Related Workmentioning
confidence: 99%