An Empirical Methodology to Evaluate Vulnerability Discovery Models

被引:27
|
作者
Massacci, Fabio [1 ]
Viet Hung Nguyen [1 ]
机构
[1] Univ Trento, DISI, Trento, TN, Italy
关键词
Software security; empirical evaluation; vulnerability discovery model; vulnerability analysis; SECURITY VULNERABILITIES; SOFTWARE-RELIABILITY; CODE CHURN; METRICS;
D O I
10.1109/TSE.2014.2354037
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Vulnerability discovery models (VDMs) operate on known vulnerability data to estimate the total number of vulnerabilities that will be reported after a software is released. VDMs have been proposed by industry and academia, but there has been no systematic independent evaluation by researchers who are not model proponents. Moreover, the traditional evaluation methodology has some issues that biased previous studies in the field. In this work we propose an empirical methodology that systematically evaluates the performance of VDMs along two dimensions (quality and predictability) and addresses all identified issues of the traditional methodology. We conduct an experiment to evaluate most existing VDMs on popular web browsers' vulnerability data. Our comparison shows that the results obtained by the proposed methodology are more informative than those by the traditional methodology. Among evaluated VDMs, the simplest linear model is the most appropriate choice in terms of both quality and predictability for the first 6-12 months since a release date. Otherwise, logistics-based models are better choices.
引用
收藏
页码:1147 / 1162
页数:16
相关论文
共 50 条
  • [21] A Geostatistical Methodology to Evaluate the Performance of Groundwater Quality Monitoring Networks Using a Vulnerability Index
    Hugo Júnez-Ferreira
    Julián González
    Emmanuel Reyes
    Graciela S. Herrera
    Mathematical Geosciences, 2016, 48 : 25 - 44
  • [22] A Geostatistical Methodology to Evaluate the Performance of Groundwater Quality Monitoring Networks Using a Vulnerability Index
    Junez-Ferreira, Hugo
    Gonzalez, Julian
    Reyes, Emmanuel
    Herrera, Graciela S.
    MATHEMATICAL GEOSCIENCES, 2016, 48 (01) : 25 - 44
  • [23] Multivariate models using MCMCBayes for web-browser vulnerability discovery
    Johnston, Reuben
    Sarkani, Shahryar
    Mazzuchi, Thomas
    Holzer, Thomas
    Eveleigh, Timothy
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2018, 176 : 52 - 61
  • [24] A Knowledge Discovery Methodology for Identifying Vulnerability Factors of Mental Disorder in an Intellectually Disabled Population
    Lluis Martorell, Xavier
    Massanet Vila, Raimon
    Gibert, Karina
    Sanchez-Marre, Miquel
    Martin, Juan Carlos
    Martorell, Almudena
    ARTIFICIAL INTELLIGENCE RESEARCH AND DEVELOPMENT, 2007, 163 : 426 - +
  • [25] Methodology to Evaluate Sensitive Levels of Inputs for US Commercial Building Models
    Ye, Yunyang
    Hinkelman, Kathryn
    Zuo, Wangda
    Wang, Gang
    ASHRAE TRANSACTIONS 2019, VOL 125, PT 2, 2019, 125 : 63 - 66
  • [26] Empirical Hardness Models: Methodology and a Case Study on Combinatorial Auctions
    Leyton-Brown, Kevin
    Nudelman, Eugene
    Shoham, Yoav
    JOURNAL OF THE ACM, 2009, 56 (04)
  • [27] Use of size spectra and empirical models to evaluate trophic relationships in streams
    Morin, A
    Bourassa, N
    Cattaneo, A
    LIMNOLOGY AND OCEANOGRAPHY, 2001, 46 (04) : 935 - 940
  • [28] A proposal and empirical validation of metrics to evaluate the maintainability of software process models
    Garcia, Felix
    Ruiz, Francisco
    Visaggio, Corrado Aaron
    2006 IEEE INSTRUMENTATION AND MEASUREMENT TECHNOLOGY CONFERENCE PROCEEDINGS, VOLS 1-5, 2006, : 1093 - +
  • [29] Processor Vulnerability Discovery
    Lyu, Yongqiang
    Sun, Rihui
    Qu, Gang
    2023 60TH ACM/IEEE DESIGN AUTOMATION CONFERENCE, DAC, 2023,
  • [30] A model to evaluate upstream vulnerability
    Gualandris, Jury
    Kalchschmidt, Matteo
    INTERNATIONAL JOURNAL OF LOGISTICS-RESEARCH AND APPLICATIONS, 2014, 17 (03) : 249 - 268