Evaluating Security of Software Through Vulnerability Metrics

Forskningsoutput: Kapitel i bok/rapport/Conference proceedingKonferenspaper i proceedingForskningPeer review

Sammanfattning

Understanding and measuring security of software
in terms of vulnerability metrics is important when reviewing
and deciding between softwares. The large number of disclosed
vulnerabilities will continue to expose software intensive
systems and products to attacks, and the choice of third
party software will affect stability and reliability of products
incorporating this software. We collect CVE data from NVD
and version release data from GitHub in order to study how
vulnerabilities, exploits and patches affect the exposure of
software. By combining all data for each software we propose
a software vulnerability exposure score that can be used
when evaluating security. We perform a large-scale study of
more than 37000 software and also analyze common web
servers and cryptographic libraries in more detail. We show
that the proposed score is both diverse and close to normally
distributed, making it attractive as a review and comparison tool.
Originalspråkengelska
Titel på gästpublikationProceedings of the 2018 International Conference on Security & Management
Sidor79
Antal sidor85
ISBN (elektroniskt)1-60132-488-X
StatusPublished - 2018
Evenemang International Conference on Security and Management (SAM'18) - Las Vegas, USA
Varaktighet: 2018 jul 302018 aug 2

Konferens

Konferens International Conference on Security and Management (SAM'18)
Land/TerritoriumUSA
OrtLas Vegas
Period2018/07/302018/08/02

Ämnesklassifikation (UKÄ)

  • Datorsystem

Citera det här