A Systematically Empirical Evaluation of Vulnerability Discovery Models: a Study on Browsers' Vulnerabilities

نویسندگان

  • Viet Hung Nguyen
  • Fabio Massacci
چکیده

A precise vulnerability discovery model (VDM) will provide a useful insight to assess software security, and could be a good prediction instrument for both software vendors and users to understand security trends and plan ahead patching schedule accordingly. Thus far, several models have been proposed and validated. Yet, no systematically independent validation by somebody other than the author exists. Furthermore, there are a number of issues that might bias previous studies in the field. In this work, we fill in the gap by introducing an empirical methodology that systematically evaluates the performance of a VDM in two aspects: quality and predictability. We further apply this methodology to assess existing VDMs. The results show that some models should be rejected outright, while some others might be adequate to capture the discovery process of vulnerabilities. We also consider different usage scenarios of VDMs and find that the simplest linear model is the most appropriate choice in terms of both quality and predictability when browsers are young. Otherwise, logistics-based models are better choices.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

An Analysis of the Vulnerability Discovery Process in Web Browsers

New vulnerabilities discovered in a web browser put millions of users at risk, requiring urgent attention from developers to address these vulnerabilities. This paper presents a quantitative characterization of browser vulnerabilities which can be used to project the number of vulnerabilities to plan, test and development resources more efficiently. Vulnerability discovery data for the three ma...

متن کامل

Thesis an Analysis of Vulnerabilities in Web Servers and Browser Using Time-base and Effort-based Models

OF THESIS AN ANALYSIS OF VULNERABILITIES IN WEB SERVERS AND BROWSER USING TIME-BASE AND EFFORT-BASED MODELS With the rapid in rease in the number of vulnerabilities dis overed in major software systems, se urity in omputing and internet-based transa tions is greatly threatened. These vulnerabilities an be exploited to damage a omputer system's se urity attributes on dentiality, integrity and av...

متن کامل

An Independent Validation of Vulnerability Discovery

Having a precise vulnerability discovery model (VDM) would provide a useful quantitative insight to assess software security. Thus far, several models have been proposed with some evidence supporting their goodness-of-fit. In this work we describe an independent validation of the applicability of six existing VDMs in seventeen releases of the three popular browsers Firefox, Google Chrome and In...

متن کامل

An Idea of an Independent Validation of Vulnerability Discovery Models

Having a precise vulnerability discovery model (VDM) would provide a useful quantitative insight to assess software security. Thus far, several models have been proposed with some evidence supporting their goodness-of-fit. In this work we describe an independent validation of the applicability of these models to the vulnerabilities of the popular browsers Firefox, Google Chrome and Internet Exp...

متن کامل

Vulnerabilities in Browsers: Trends in Internet Explorer and Firefox

Since the browsers serve as the gateway to the web, vulnerabilities in browsers can have great impact. Recently there has been considerable debate about the vulnerabilities in the two major browsers Microsoft Internet Explorer and Mozilla Firefox which represent two opposite development paradigms. Here we present a quantitative perspective involving vulnerability detection rates, severity and p...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • CoRR

دوره abs/1306.2476  شماره 

صفحات  -

تاریخ انتشار 2013