共 50 条
The Secret Life of CVEs
被引:0
|作者:
Przymus, Piotr
[1
]
Fejzer, Mikolaj
[1
]
Narebski, Jakub
[1
]
Stencel, Krzysztof
[2
]
机构:
[1] Nicolaus Copernicus Univ, Torun, Poland
[2] Univ Warsaw, Warsaw, Poland
关键词:
CVE;
Mining software repositories;
Software quality;
Survival analysis;
D O I:
10.1109/MSR59073.2023.00056
中图分类号:
TP31 [计算机软件];
学科分类号:
081202 ;
0835 ;
摘要:
The Common Vulnerabilities and Exposures (CVEs) system is a reference method for documenting publicly known information security weaknesses and exposures. This paper presents a study of the lifetime of CVEs in software projects and the risk factors affecting their existence. The study uses survival analysis to examine how features of programming languages, projects, and CVEs themselves impact the lifetime of CVEs. We suggest avenues for future research to investigate the effect of various factors on the resolution of vulnerabilities.
引用
收藏
页码:362 / 366
页数:5
相关论文