首页> 外文会议>2018 International Arab Conference on Information Technology >Measuring Impact Score on Confidentiality, Integrity, and Availability Using Code Metrics
【24h】

Measuring Impact Score on Confidentiality, Integrity, and Availability Using Code Metrics

机译:使用代码指标衡量对机密性,完整性和可用性的影响得分

获取原文
获取原文并翻译 | 示例

摘要

Confidentiality, Integrity, and Availability are principal keys to build any secure software. Considering the security principles during the different software development phases would reduce software vulnerabilities. This paper measures the impact of the different software quality metrics on Confidentiality, Integrity, or Availability for any given object-oriented PHP application, which has a list of reported vulnerabilities. The National Vulnerability Database was used to provide the impact score on confidentiality, integrity, and availability for the reported vulnerabilities on the selected applications. This paper includes a study for these scores and its correlation with 25 code metrics for the given vulnerable source code. The achieved results were able to correlate 23.7% of the variability in ‘Integrity’ to four metrics: Vocabulary Used in Code, Card and Agresti, Intelligent Content, and Efferent Coupling metrics. The Length (Halstead metric) could alone predict about 24.2 % of the observed variability in ‘ Availability’. The results indicate no significant correlation of ‘Confidentiality’ with the tested code metrics.
机译:机密性,完整性和可用性是构建任何安全软件的主要关键。在不同软件开发阶段考虑安全原则将减少软件漏洞。本文测量了不同软件质量指标对任何给定的面向对象PHP应用程序的机密性,完整性或可用性的影响,该应用程序列出了已报告的漏洞。国家漏洞数据库用于提供所选应用程序上报告的漏洞的机密性,完整性和可用性的影响评分。本文针对这些得分进行了研究,并将其与给定易受攻击的源代码的25个代码指标进行了关联。取得的成果能够将“完整性”中23.7%的可变性与四个指标相关联:代码,卡和Agresti中使用的词汇量,智能内容和传出耦合指标。长度(Halstead指标)可以单独预测“可用性”中观察到的变化的24.2 \%。结果表明“机密性”与经过测试的代码指标之间没有显着相关性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号