An Empirical Methodology to Evaluate Vulnerability Discovery Models

被引:27
|
作者
Massacci, Fabio [1 ]
Viet Hung Nguyen [1 ]
机构
[1] Univ Trento, DISI, Trento, TN, Italy
关键词
Software security; empirical evaluation; vulnerability discovery model; vulnerability analysis; SECURITY VULNERABILITIES; SOFTWARE-RELIABILITY; CODE CHURN; METRICS;
D O I
10.1109/TSE.2014.2354037
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Vulnerability discovery models (VDMs) operate on known vulnerability data to estimate the total number of vulnerabilities that will be reported after a software is released. VDMs have been proposed by industry and academia, but there has been no systematic independent evaluation by researchers who are not model proponents. Moreover, the traditional evaluation methodology has some issues that biased previous studies in the field. In this work we propose an empirical methodology that systematically evaluates the performance of VDMs along two dimensions (quality and predictability) and addresses all identified issues of the traditional methodology. We conduct an experiment to evaluate most existing VDMs on popular web browsers' vulnerability data. Our comparison shows that the results obtained by the proposed methodology are more informative than those by the traditional methodology. Among evaluated VDMs, the simplest linear model is the most appropriate choice in terms of both quality and predictability for the first 6-12 months since a release date. Otherwise, logistics-based models are better choices.
引用
收藏
页码:1147 / 1162
页数:16
相关论文
共 50 条
  • [1] Empirical characterization of the likelihood of vulnerability discovery
    Wilhjelm C.
    Kotadiya T.
    Younis A.A.
    International Journal of Performability Engineering, 2020, 16 (07) : 1008 - 1018
  • [2] An Empirical Study of Web Vulnerability Discovery Ecosystems
    Zhao, Mingyi
    Grossklags, Jens
    Liu, Peng
    CCS'15: PROCEEDINGS OF THE 22ND ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2015, : 1105 - 1117
  • [3] An Independent Validation of Vulnerability Discovery Models
    Viet Hung Nguyen
    Massacci, Fabio
    7TH ACM SYMPOSIUM ON INFORMATION, COMPUTER AND COMMUNICATIONS SECURITY (ASIACCS 2012), 2012,
  • [4] Prediction capabilities of vulnerability discovery models
    Alhazmi, Omar H.
    Malaiya, Yashwant K.
    2006 PROCEEDINGS - ANNUAL RELIABILITY AND MAINTAINABILITY SYMPOSIUM, VOLS 1 AND 2, 2006, : 86 - +
  • [5] Relating the Empirical Foundations of Attack Generation and Vulnerability Discovery
    Westland, Tyler
    Niu, Nan
    Jha, Rashmi
    Kapp, David
    Kebede, Temesguen
    2020 IEEE 21ST INTERNATIONAL CONFERENCE ON INFORMATION REUSE AND INTEGRATION FOR DATA SCIENCE (IRI 2020), 2020, : 37 - 44
  • [6] Vulnerability prediction capability: A comparison between vulnerability discovery models and neural network models
    Movahedi, Yazdan
    Cukier, Michel
    Gashi, Ilir
    COMPUTERS & SECURITY, 2019, 87
  • [7] Application of Empirical Methodology to Evaluate Information Fusion Approaches
    Ziegler, Juergen
    Detje, Frank
    2013 16TH INTERNATIONAL CONFERENCE ON INFORMATION FUSION (FUSION), 2013, : 1878 - 1885
  • [8] An Idea of an Independent Validation of Vulnerability Discovery Models
    Viet Hung Nguyen
    Massacci, Fabio
    ENGINEERING SECURE SOFTWARE AND SYSTEMS, 2012, 7159 : 89 - 96
  • [9] How to evaluate plaque vulnerability in animal models of atherosclerosis?
    Rekhter, MD
    CARDIOVASCULAR RESEARCH, 2002, 54 (01) : 36 - 41
  • [10] METHODOLOGY TO EVALUATE NUCLEAR POWER PLANT VULNERABILITY TO EVENTS IN THE TRANSMISSION GRID
    Del Rosso, Alberto
    Roy, Jean-Francois
    Rahn, Frank
    Capara, Alejandro
    PROCEEDINGS OF THE 22ND INTERNATIONAL CONFERENCE ON NUCLEAR ENGINEERING - 2014, VOL 3, 2014,