A Quantitative Approach
نویسندگان
چکیده
Accuvant LABS built criteria and comparatively analyzed the security of Google Chrome, Microsoft Internet Explorer, and Mozilla FireFox. While similar comparisons have been performed in the past, previous studies compared browser security by considering metrics such as vulnerability report counts and URL blacklists. This paper takes a fundamentally different approach, examining which security metrics are most effective in protecting end users and evaluating those criteria using publicly available data and independently verifiable techniques. Most attempts to compare the security of different vendors within a software class rely on statistical analysis of vulnerability data. The section entitled Historical Vulnerability Statistics and its subsections examine publicly available vulnerability data and discuss why such an approach is limited in its usefulness for comparatively assessing security. In contrast, we believe an analysis of anti-exploitation techniques is the most effective way to compare security between browser vendors. This requires a greater depth of technical expertise than statistical analysis of CVEs, but it provides a more accurate window into the vulnerabilities of each browser. Accuvant LABS' analysis is based on the premise that all software of sufficient complexity and an evolving code base will always have vulnerabilities. Anti-exploitation technology can reduce or eliminate the severity of a single vulnerability or an entire class of exploits. Thus, the software with the best anti-exploitation technologies is likely to be the most resistant to attack and is the most crucial consideration in browser security. An important difference between this paper and previous studies is that we've made our data and the tools used to derive the data available for scrutiny. Previous attempts have been made to compare Historical Vulnerability Statistics and URL Blacklist Services; however, those studies' conclusions have differed wildly from this paper's results, and the difference in outcomes arises largely from the choice of data sources. We believe our own data is correctly representative of the population and have made it, along with our tools and methodologies, available to test this belief. Finally, we invite others to examine the tools for issues, or to extend and improve on them to encompass more criteria. We hope this paper presents readers with a definitive statement as to which browser is currently the most secure against common attacks, and provides criterion that vendors may use to measure and improve the security posture of their browsers. Finally, it is our hope that this is helpful to others who work to evaluate …
منابع مشابه
Determining Teachers’ Professional Qualifications in “The Learning Approach to Knowing” and Presenting Executive Strategies for Realization of this Approach: A Mixed-Method Research
The present study aims at determining teachers’ professional qualifications in “the learning approach to knowing” and presenting executive strategies for realization of this approach. The research employs an exploratory mixed-method research. The population in the qualitative part of the research consists of experts of education and in the quantitative part includes all high school teachers of ...
متن کاملCrime Prevention in Urban Design: towards Space Syntax Approach as a Quantitative Analytic Modeling of Qualitative Issue of Security (Based on Spatial Configuration)
متن کامل
Proposing a quantitative approach to measure the success of energy management systems in accordance with ISO 50001: 2011 using an analytical hierarchy process (AHP)
ISO 50001: 2011 provides an integrated and systematic framework to plan, implement, operate, certify, and maintain energy management systems (EMSs). Evaluation of organizations in relation to meeting the standard requirements is performed by an auditing qualitative approach. In this research, a quantitative approach has been proposed and implemented to assess organizations and rank them based o...
متن کاملQualitative and quantitative approaches to analyse reliability of a mechatronic system: a case
The main research intent of this paper is to introduce the use of fault tree analysis (FTA) and failure mode and effects analysis (FMEA) in conjunction to analyse the risk and reliability of a complex mechatronic system in both qualitative and quantitative manner. The major focus is on handling imprecise and vague information with the help of fuzzy synthesis of information. A complex mechatroni...
متن کاملComparison of Strategic Plans of Universities and Institutes of Higher Education with a Quantitative Approach
Strategic planning in Iranian universities and institutes of higher education is generally prepared using strategic planning models introduced by experts and other universities. These programs will be published in the form of university strategic planning documents. These documents have such features that can be similar or different than the programming templates used. Existence of the similar...
متن کاملThree-dimensional quantitative structure activity relationship approach series of 3-Bromo-4-(1-H-3-Indolyl)-2, 5-Dihydro-1H-2, 5- Pyrroledione as antibacterial agents
The use of quantitative structure–activity relationships, since its advent, has becomeincreasingly helpful in understanding many aspects of biochemical interactions in drug research.This approach was utilized to explain the relationship of structure with biological activity ofantibacterial. For the development of new fungicides against, the quantitative structural–activityrelationship (QSAR) an...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2011