作者
Omar Hussain Alhazmi, Yashwant K Malaiya, Indrajit Ray
发表日期
2007/5/1
期刊
computers & security
卷号
26
期号
3
页码范围
219-228
出版商
Elsevier Advanced Technology
简介
In this work we examine the feasibility of quantitatively characterizing some aspects of security. In particular, we investigate if it is possible to predict the number of vulnerabilities that can potentially be present in a software system but may not have been found yet. We use several major operating systems as representatives of complex software systems. The data on vulnerabilities discovered in these systems are analyzed. We examine the results to determine if the density of vulnerabilities in a program is a useful measure. We also address the question about what fraction of software defects are security related, i.e., are vulnerabilities. We examine the dynamics of vulnerability discovery hypothesizing that it may lead us to an estimate of the magnitude of the undiscovered vulnerabilities still present in the system. We consider the vulnerability discovery rate to see if models can be developed to project future trends …
引用总数
20062007200820092010201120122013201420152016201720182019202020212022202320241591618121218171932273940252317176