Periodicity in software vulnerability discovery, patching and exploitation

被引:0
|
作者
HyunChul Joh
Yashwant K. Malaiya
机构
[1] Kyungil University,Department of Computer Engineering
[2] Colorado State University,Computer Science Department
关键词
Vulnerability; Laws of vulnerabilities; Seasonality; Periodicity; Operating system;
D O I
暂无
中图分类号
学科分类号
摘要
Periodicity in key processes related to software vulnerabilities need to be taken into account for assessing security at a given time. Here, we examine the actual multi-year field datasets for some of the most used software systems (operating systems and Web-related software) for potential annual variations in vulnerability discovery processes. We also examine weekly periodicity in the patching and exploitation of the vulnerabilities. Accurate projections of the vulnerability discovery process are required to optimally allocate the effort needed to develop patches for handling discovered vulnerabilities. A time series analysis that combines the periodic pattern and longer-term trends allows the developers to predict future needs more accurately. We analyze eighteen datasets of software systems for annual seasonality in their vulnerability discovery processes. This analysis shows that there are indeed repetitive annual patterns. Next, some of the datasets from a large number of major organizations that record the result of daily scans are examined for potential weekly periodicity and its statistical significance. The results show a 7-day periodicity in the presence of unpatched vulnerabilities, as well as in the exploitation pattern. The seasonal index approach is used to examine the statistical significance of the observed periodicity. The autocorrelation function is used to identify the exact periodicity. The results show that periodicity needs to be considered for optimal resource allocations and for evaluation of security risks.
引用
收藏
页码:673 / 690
页数:17
相关论文
共 50 条
  • [21] Patching A Patch - Software Updates Using Horizontal Patching
    Stolikj, Milosh
    Cuijpers, Pieter J. L.
    Lukkien, Johan J.
    2013 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS (ICCE), 2013, : 647 - 648
  • [22] Patching a Patch - Software Updates Using Horizontal Patching
    Stolikj, Milosh
    Cuijpers, Pieter J. L.
    Lukkien, Johan J.
    IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2013, 59 (02) : 435 - 441
  • [23] A Game Theoretic approach to Vulnerability Patching
    Gianini, Gabriele
    Cremonini, Marco
    Rainini, Andrea
    Cota, Guido Lena
    Fossi, Leopold Ghemmogne
    2015 INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY RESEARCH (ICTRC), 2015, : 88 - 91
  • [24] Modeling Software Vulnerability Discovery Process Inculcating the Impact of Reporters
    Adarsh Anand
    Navneet Bhatt
    Omar H. Alhazmi
    Information Systems Frontiers, 2021, 23 : 709 - 722
  • [25] Deep Neural Embedding for Software Vulnerability Discovery: Comparison and Optimization
    Yuan, Xue
    Lin, Guanjun
    Tai, Yonghang
    Zhang, Jun
    Security and Communication Networks, 2022, 2022
  • [26] Cybersecurity: a predictive analytical model for software vulnerability discovery process
    Pokhrel, Nawa Raj
    Khanal, Netra
    Tsokos, Chris P.
    Pokhrel, Keshav
    Pokhrel, Nawa Raj (npokhrel@xula.edu), 1600, Taylor and Francis Ltd. (05): : 41 - 69
  • [27] Deep Neural Embedding for Software Vulnerability Discovery: Comparison and Optimization
    Yuan, Xue
    Lin, Guanjun
    Tai, Yonghang
    Zhang, Jun
    SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [28] Software security evaluation using multilevel vulnerability discovery modeling
    Sharma, Ruchi
    Shrivastava, Avinash K.
    Hoang Pham
    QUALITY ENGINEERING, 2023, 35 (02) : 341 - 352
  • [29] CLORIFI: software vulnerability discovery using code clone verification
    Li, Hongzhe
    Kwon, Hyuckmin
    Kwon, Jonghoon
    Lee, Heejo
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2016, 28 (06): : 1900 - 1917
  • [30] Modeling Software Vulnerability Discovery Process Inculcating the Impact of Reporters
    Anand, Adarsh
    Bhatt, Navneet
    Alhazmi, Omar H.
    INFORMATION SYSTEMS FRONTIERS, 2021, 23 (03) : 709 - 722