作者
Omar H Alhazmi, Yashwant K Malaiya
发表日期
2006/1/23
研讨会论文
RAMS'06. Annual Reliability and Maintainability Symposium, 2006.
页码范围
86-91
出版商
IEEE
简介
Quantitative approaches for software security are needed for effective testing, maintenance and risk assessment of software systems. Vulnerabilities that are present in an operating system after its release represent a great risk. Vulnerability discovery models (VDMs) have been proposed to model vulnerability discovery and have has been fined to vulnerability data against calendar time. The models have been shown to fit very well. In this paper, we investigate the prediction capabilities that these models offer by evaluating accuracy of predictions made with partial data. We examine both the recently proposed logistic model and a new linear model. In addition to VDMs, we consider static approaches to estimating some of the major attributes of the vulnerability discovery process, presenting a static approach to estimating the initial values of one of the VDM's parameters. We also suggest the use of constraints for …
引用总数
2005200620072008200920102011201220132014201520162017201820192020202120222023143412435958751011472
学术搜索中的文章
OH Alhazmi, YK Malaiya - RAMS'06. Annual Reliability and Maintainability …, 2006