Milk or wine: Does software security improve with age?

被引:0
|
作者
Oment, Andy [1 ]
Schechter, Stuart E. [1 ]
机构
[1] MIT, Lincoln Lab, Cambridge, MA 02139 USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We examine the code base of the OpenBSD operating system to determine whether its security is increasing over time. We measure the rate at which new code has been introduced and the rate at which vulnerabilities have been reported over the last 7.5 years and fifteen versions. We learn that 61% of the lines of code in today's OpenBSD are foundational: they were introduced prior to the release of the initial version we studied and have not been altered since. We also learn that 62% of reported vulnerabilities were present when the study began and can also be considered to be foundational. We find strong statistical evidence of a decrease in the rate at which foundational vulnerabilities are being reported. However, this decrease is anything but brisk: foundational vulnerabilities have a median lifetime of at least 2.6 years. Finally, we examined the density of vulnerabilities in the code that was altered/introduced in each version. The densities ranged from 0 to 0.033 vulnerabilities reported per thousand lines of code. These densities will increase as more vulnerabilities are reported.
引用
收藏
页码:93 / 104
页数:12
相关论文
共 50 条
  • [21] TURNING WINE INTO MILK
    不详
    FOOD AUSTRALIA, 2012, 64 (01): : 38 - 38
  • [22] BUY WINE AND MILK
    不详
    LANCET, 1966, 2 (7478): : 1402 - &
  • [23] Does training improve security decisions? A case study of airports
    Kirschenbaum, Alan
    Rapaport, Carmit
    SECURITY JOURNAL, 2017, 30 (01) : 184 - 198
  • [24] Does energy security improve renewable energy? A geopolitical perspective
    Khan, Khalid
    Su, Chi Wei
    Khurshid, Adnan
    Qin, Meng
    ENERGY, 2023, 282
  • [25] Does training improve security decisions? A case study of airports
    Alan (Avi) Kirschenbaum
    Carmit Rapaport
    Security Journal, 2017, 30 : 184 - 198
  • [26] Does Centralized Data Management Software Improve Patient Care?
    Schneider, K.
    Martinez, M.
    Shalaby, J.
    Penafiel, V.
    Jenkins, F.
    Dunn, D.
    TRANSFUSION, 2024, 64 : 192A - 193A
  • [27] The antioxidant activity of Californian red wines does not correlate with wine age
    Roginsky, V
    de Beer, D
    Harbertson, JF
    Kilmartin, PA
    Barsukoval, T
    Adams, DO
    JOURNAL OF THE SCIENCE OF FOOD AND AGRICULTURE, 2006, 86 (05) : 834 - 840
  • [28] Software for Improve the Security of Kubernetes-based CI/CD Pipeline
    Shevchuk, Ruslan
    Karpinski, Mikolaj
    Kasianchuk, Mykhailo
    Yakymenko, Ihor
    Melnyk, Andriy
    Tykhyi, Roman
    Proceedings - International Conference on Advanced Computer Information Technologies, ACIT, 2023, : 420 - 425
  • [29] How to use Software-Defined Networking to Improve Security - a Survey
    Proenca, Jorge
    Cruz, Tiago
    Monteiro, Edmundo
    Simoes, Paulo
    PROCEEDINGS OF THE 14TH EUROPEAN CONFERENCE ON CYBER WARFARE AND SECURITY (ECCWS-2015), 2015, : 220 - 228
  • [30] Using Multi-Level Security Annotations to Improve Software Assurance
    Kylikowski, Eryk
    Scandariato, Riccardo
    Joosen, Wouter
    11TH IEEE HIGH ASSURANCE SYSTEMS ENGINEERING SYMPOSIUM, PROCEEDINGS, 2008, : 471 - 474