Milk or wine: Does software security improve with age?

被引:0
|
作者
Oment, Andy [1 ]
Schechter, Stuart E. [1 ]
机构
[1] MIT, Lincoln Lab, Cambridge, MA 02139 USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We examine the code base of the OpenBSD operating system to determine whether its security is increasing over time. We measure the rate at which new code has been introduced and the rate at which vulnerabilities have been reported over the last 7.5 years and fifteen versions. We learn that 61% of the lines of code in today's OpenBSD are foundational: they were introduced prior to the release of the initial version we studied and have not been altered since. We also learn that 62% of reported vulnerabilities were present when the study began and can also be considered to be foundational. We find strong statistical evidence of a decrease in the rate at which foundational vulnerabilities are being reported. However, this decrease is anything but brisk: foundational vulnerabilities have a median lifetime of at least 2.6 years. Finally, we examined the density of vulnerabilities in the code that was altered/introduced in each version. The densities ranged from 0 to 0.033 vulnerabilities reported per thousand lines of code. These densities will increase as more vulnerabilities are reported.
引用
收藏
页码:93 / 104
页数:12
相关论文
共 50 条
  • [1] Like milk or wine: Does firm performance improve with age?
    Coad, Alex
    Segarra, Agusti
    Teruel, Mercedes
    STRUCTURAL CHANGE AND ECONOMIC DYNAMICS, 2013, 24 : 173 - 189
  • [2] Patients age: so does wine
    Shaun R. McCann
    Bone Marrow Transplantation, 2019, 54 : 1725 - 1727
  • [3] Patients age: so does wine
    McCann, Shaun R.
    BONE MARROW TRANSPLANTATION, 2019, 54 (11) : 1725 - 1727
  • [4] To ensure security, improve software quality
    Hoepman, Jaap-Henk
    Jacobs, Bart
    COMMUNICATIONS OF THE ACM, 2007, 50 (08) : 14 - 14
  • [5] Standing the test of time. Does firm performance improve with age? An analysis of the wine industry
    Capasso, Arturo
    Gallucci, Carmen
    Rossi, Matteo
    BUSINESS HISTORY, 2015, 57 (07) : 1037 - 1053
  • [6] Approach Uses Software Analysis to Improve Security
    不详
    COMPUTER, 2010, 43 (02) : 17 - 18
  • [7] Using complexity metrics to improve software security
    Moshtari, Sara
    Sami, Ashkan
    Azimi, Mahdi
    Computer Fraud and Security, 2013, 2013 (05): : 8 - 17
  • [8] Does a glass of red wine improve endothelial function?
    Agewall, S
    Wright, S
    Doughty, RN
    Whalley, GA
    Duxbury, M
    Sharpe, N
    EUROPEAN HEART JOURNAL, 2000, 21 (01) : 74 - 78
  • [9] Does boiling improve the keeping properties of milk?
    Bevan, R
    LANCET, 1904, 2 : 639 - 639
  • [10] Does open source improve system security?
    Witten, B
    Landwehr, C
    Caloyannides, M
    IEEE SOFTWARE, 2001, 18 (05) : 57 - +