Modeling Learningless Vulnerability Discovery using a Folded Distribution

نویسندگان

  • Awad A. Younis
  • HyunChul Joh
  • Yashwant K. Malaiya
چکیده

A vulnerability discovery model describes the vulnerability discovery rate in a software system, and predicts the future behavior. It can allow the IT managers and developers to allocate their resources optimally by timely development and application of patches. Such models also allow the end-users to assess security risk in their systems. Recently, researchers have proposed a few vulnerability discovery models. The models are based on different assumptions, and thus differ in their accuracy and prediction capabilities. Among these models, the AML model has been found to have performed better in many cases in terms of model fitting and prediction capabilities. The AML model assumes that the discovery rate is symmetric. However, it has been noted that there are cases when the discovery trend is asymmetric. In this paper, we investigate the applicability of using a new vulnerability discovery model called Folded model, based on the Folded normal distribution, and compare it with the AML model. Results show that Folded model performs better than the AML model in general for both model fitting and prediction capabilities in cases when the learning phase is not present.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

FAST ABSTRACT: Vulnerability Discovery Modeling using Weibull Distribution

A vulnerability discovery model describes the variation in the vulnerability discovery rate during the lifetime of a software system and can be used to assess risk and to evaluate possible mitigation approaches. A few vulnerability discovery models have recently been proposed. The AML Logistic model has been found to provide the best fit in several cases. Weibull distribution, which can model a...

متن کامل

Modeling vulnerability discovery process in Apache and IIS HTTP servers

Vulnerability discovery models allow prediction of the number of vulnerabilities that are likely to be discovered in the future. Hence, they allow the vendors and the end users to manage risk by optimizing resource allocation. Most vulnerability discovery models proposed use the time as an independent variable. Effort-based modeling has also been proposed, which requires the use of market share...

متن کامل

Modeling the spatial distribution of mood disorders in Isfahan Province, Iran

Backgrand and aim: the physical and the social environments are effective on personality traits. What is in the frame-work of medical geography, is physical environment that can has positive effect on the human psyche it can also has sometimes negative effects as well,that investigating of this effect is in the field of medical geographers.Methods: The present study is descriptive analyti...

متن کامل

Modeling Security Vulnerabilities in Learning Management Systems

In many educational institutes, learning management systems are essential parts of delivering class materials not only for on-line courses but also on-campus classes. The primary purpose of learning management system is to provide proper virtual educational environments and convenient communicational channels between instructors and students letting them to overcome the barrier of time and spac...

متن کامل

Discovery of Novel Glucagon Receptor Antagonists Using Combined Pharmacophore Modeling and Docking

Glucagon and the glucagon receptor are most important molecules control over blood glucose concentrations. These two molecules are very important to studies of type 2 diabetic patients. In literature, several classes of small molecule antagonists of the human glucagon receptor have been reported. Glucagon receptor antagonist could decrease hepatic glucose output and improve glucose control in d...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2011