The life and death of statically detected vulnerabilities: An empirical study
نویسندگان
چکیده
Vulnerable statements constitute a major problem for developers and maintainers of networking systems. Their presence can ease the success of security attacks, aimed at gaining unauthorized access to data and functionality, or at causing system crashes and data loss. Examples of attacks caused by source code vulnerabilities are buffer overflows, command injections, and cross-site scripting. This paper reports on an empirical study, conducted across four networking systems, aimed at observing the evolution and decay of vulnerabilities detected by three freely available static analysis tools. In particular, the study compares the decay of different kinds of vulnerabilities, characterizes the decay likelihood through probability density functions, and reports a quantitative and qualitative analysis of the reasons for vulnerability removals. The study is performed by using a framework that traces the evolution of source code fragments across subsequent commits.
منابع مشابه
Perfectionism and Stressful Life Events as Vulnerabilities to Depression Symptoms in Students
IntroductionThe mood disorders such as depression are the most common mental disorders among individuals. In addition to, girls’ students as a group at high risk are known for developing this disorder. The aim of this study was to investigate the role of perfectionism and stressful life events in predicting disordered depression symptoms among girls’ students. Materials and Methods: This cross-...
متن کاملمهارت های زندگی و پیشگیری از اعتیاد
Socially vulnerable people such as drug abusers have limited life skills to deal with social issues and social challenges. These people are not able to make appropriate and effective decisions in different and difficult situations in life, or choose the appropriate reconciliation strategy, due to the lack of knowledge and skills, as well as the plurality of problems and difficulties in life. Fo...
متن کاملRole of Crisis Management in Reducing Socio-Psychological Vulnerabilities after Natural Disasters (Case study: Citizens of Bam City)
Natural disasters in various forms have been identified as destructive phenomena during the life of earth planet and are also a serious threat to the inhabitants of the planet. Therefore, this issue leaded to the formation of a process called crisis management which includes activities occurring before, within and after the event to reduce the vulnerability. The country of Iran is considered as...
متن کاملComparison of Quality of Life, Life Satisfaction and Death Anxiety among Intra-Oriented and Outward Elderly
The purpose of this study was to compare the quality of life, life satisfaction, and death anxiety among internally oriented and out-of-home elderly in the home and home of the elderly in Kermanshah in 1396. The statistical population of the study included all elderly people in Kermanshah. A total of 168 people were selected through cluster sampling and elderly residents of the elderly in an ac...
متن کاملConsequences of Death Awareness in Adolescents' Lives: A Qualitative Study
Aim: The present research intended to investigate the outcomes of death awareness in life from the perspective of Iranian adolescents. Methods: The study employed a phenomenological qualitative approach. The participants included 26 male and female high school students aged 16 to 18 going to schools in Tehran province, who were selected through criterion purposive sampling method. To collect da...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- Information & Software Technology
دوره 51 شماره
صفحات -
تاریخ انتشار 2009