作者
Omar Alhazmi, Yashwant Malaiya, Indrajit Ray
发表日期
2005/8/7
图书
IFIP Annual Conference on Data and Applications Security and Privacy
页码范围
281-294
出版商
Springer Berlin Heidelberg
简介
Security and reliability are important attributes of complex software systems. It is now common to use quantitative methods for evaluating and managing reliability. In this work we examine the feasibility of quantitatively characterizing some aspects of security.In particular, we investigate if it is possible to predict the number of vulnerabilities that can potentially be identified in a future release of a software system. We use several major operating systems as representatives of complex software systems. The data on vulnerabilities discovered in some of the popular operating systems is analyzed. We examine this data to determine if the density of vulnerabilities in a program is a useful measure. We try to identify what fraction of software defects are security related, i.e., are vulnerabilities. We examine the dynamics of vulnerability discovery hypothesizing that it may lead us to an estimate of the magnitude of the …
引用总数
2005200620072008200920102011201220132014201520162017201820192020202120222023202411010214577555567663432
学术搜索中的文章
O Alhazmi, Y Malaiya, I Ray - IFIP Annual Conference on Data and Applications …, 2005