...
首页> 外文期刊>International Journal of Information Technology and Computer Science >Evaluating and Comparing Size, Complexity and Coupling Metrics as Web Applications Vulnerabilities Predictors
【24h】

Evaluating and Comparing Size, Complexity and Coupling Metrics as Web Applications Vulnerabilities Predictors

机译:评估和比较作为Web应用程序漏洞预测因素的大小,复杂性和耦合指标

获取原文
   

获取外文期刊封面封底 >>

       

摘要

Most security and privacy issues in software are related to exploiting code vulnerabilities. Many studies have tried to find the correlation between the software characteristics (complexity, coupling, etc.) quantified by corresponding code metrics and its vulnerabilities and to propose automatic prediction models that help developers locate vulnerable components to minimize maintenance costs. The results obtained by these studies cannot be applied directly to web applications because a web application differs in many ways from a non-web application: development, use, etc. and a lot of evaluation of these conclusions has to be made. The purpose of this study is to evaluate and compare the vulnerabilities prediction power of three types of code metrics in web applications. There are a few similar studies that targeted non-web application and to the best of our knowledge, there are no similar studies that targeted web applications. The results obtained show that unlike non-web applications where complexity metrics have better vulnerability prediction power, in web applications the metrics that give better prediction are the coupling metrics with high recall ( 75%) and fewer costs in terms of inspection (25%).
机译:软件中的大多数安全性和隐私问题与利用代码漏洞有关。许多研究试图找到由相应代码度量量化的软件特性(复杂性,耦合性等)与其漏洞之间的相关性,并提出自动预测模型,以帮助开发人员定位易受攻击的组件,以最大程度地降低维护成本。这些研究获得的结果不能直接应用于Web应用程序,因为Web应用程序与非Web应用程序在很多方面都存在差异:开发,使用等,并且必须对这些结论进行大量评估。这项研究的目的是评估和比较Web应用程序中三种类型的代码度量标准的漏洞预测能力。有一些针对非Web应用程序的类似研究,据我们所知,没有针对Web应用程序的类似研究。所获得的结果表明,与非Web应用程序不同,非Web应用程序的复杂性指标具有更好的漏洞预测能力,而在Web应用程序中,提供更好预测的指标是具有较高召回率(> 75%)和检查成本(<25 %)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号