An Empirical Methodology to Evaluate Vulnerability Discovery Models

被引:27
|
作者
Massacci, Fabio [1 ]
Viet Hung Nguyen [1 ]
机构
[1] Univ Trento, DISI, Trento, TN, Italy
关键词
Software security; empirical evaluation; vulnerability discovery model; vulnerability analysis; SECURITY VULNERABILITIES; SOFTWARE-RELIABILITY; CODE CHURN; METRICS;
D O I
10.1109/TSE.2014.2354037
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Vulnerability discovery models (VDMs) operate on known vulnerability data to estimate the total number of vulnerabilities that will be reported after a software is released. VDMs have been proposed by industry and academia, but there has been no systematic independent evaluation by researchers who are not model proponents. Moreover, the traditional evaluation methodology has some issues that biased previous studies in the field. In this work we propose an empirical methodology that systematically evaluates the performance of VDMs along two dimensions (quality and predictability) and addresses all identified issues of the traditional methodology. We conduct an experiment to evaluate most existing VDMs on popular web browsers' vulnerability data. Our comparison shows that the results obtained by the proposed methodology are more informative than those by the traditional methodology. Among evaluated VDMs, the simplest linear model is the most appropriate choice in terms of both quality and predictability for the first 6-12 months since a release date. Otherwise, logistics-based models are better choices.
引用
收藏
页码:1147 / 1162
页数:16
相关论文
共 50 条
  • [31] A Methodology to Evaluate the Vulnerability of the Natural Gas Supply Chain Based on Set Pair Analysis and Markov Chain
    Yu, Weichao
    Zheng, Xianbin
    Wen, Feng
    Li, Lin
    Yue, Yuanzhi
    Shi, Feng
    Yang, Hong
    Liu, Yang
    Liu, Xiaoben
    JOURNAL OF PIPELINE SYSTEMS ENGINEERING AND PRACTICE, 2023, 14 (02)
  • [32] Measuring and enhancing prediction capabilities of vulnerability discovery models for Apache and IISHTTP servers
    Alhazmi, Omar H.
    Malaiya, Yashwant K.
    ISSRE 2006:17TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING, PROCEEDINGS, 2006, : 343 - +
  • [33] Induction of comprehensible models for gene expression datasets by subgroup discovery methodology
    Gamberger, D
    Lavrac, N
    Zelezny, F
    Tolar, J
    JOURNAL OF BIOMEDICAL INFORMATICS, 2004, 37 (04) : 269 - 284
  • [34] Methodology to evaluate the performance of simulation models for alternative compiler and operating system configurations
    Thorp, K. R.
    White, J. W.
    Porter, C. H.
    Hoogenboom, G.
    Nearing, G. S.
    French, A. N.
    COMPUTERS AND ELECTRONICS IN AGRICULTURE, 2012, 81 : 62 - 71
  • [35] Comparison of empirical structural vulnerability rapid prediction models considering typical earthquakes
    Li, Si-Qi
    STRUCTURES, 2023, 49 : 377 - 401
  • [36] Empirical vulnerability estimation models considering updating the structural earthquake damage database
    Li, Si-Qi
    SOIL DYNAMICS AND EARTHQUAKE ENGINEERING, 2023, 169
  • [37] An empirical study of text-based machine learning models for vulnerability detection
    Napier, Kollin
    Bhowmik, Tanmay
    Wang, Shaowei
    EMPIRICAL SOFTWARE ENGINEERING, 2023, 28 (02)
  • [38] Identification of dynamic diagnostic models with the use of methodology of knowledge discovery in databases
    Wachla, Dominik
    Moczulski, Wojciech A.
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2007, 20 (05) : 699 - 707
  • [39] Empirical seismic vulnerability models for building clusters considering hybrid intensity measures
    Li, Si-Qi
    Gardoni, Paolo
    JOURNAL OF BUILDING ENGINEERING, 2023, 68
  • [40] Vulnerability models of brick and wood structures considering empirical seismic damage observations
    Li, Si-Qi
    Liu, Hong-Bo
    Chen, Yong-Sheng
    STRUCTURES, 2021, 34 : 2544 - 2565