...
首页> 外文期刊>Journal of software: evolution and process >A comprehensive study on security bug characteristics
【24h】

A comprehensive study on security bug characteristics

机译:安全臭虫特征的综合研究

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Security bugs can catastrophically impact our increasingly digital lives. Designingeffective tools for detecting and fixing software security bugs requires a deepunderstanding of security bug characteristics. In this paper, we conducted acomprehensive study on security bugs and proposed the classification criteria forsecurity bug category, that is, root cause, consequence, and location. In addition, weselected 1076 bug reports from five projects (i.e., Apache Tomcat, Apache HTTPServer, Mozilla Firefox, Linux Kernel, and Eclipse) in the NVD for investigation.Finally, we investigated the correlation between the classification results andobtained some findings: (1) memory operation is the most common security bug;(2) the primary root causes of security bugs are CON (Configuration Error), INP (InputValidation Error), and MEM (Memory Error); (3) the severity of more than 40% ofsecurity bugs is high; (4) security bugs caused by INP mainly occur on web; and(5) security bugs caused by LOG (Logic Resource Error) usually lead to DoS (Denial ofService). We discussed these findings through data analysis, which can also helpdevelopers better understand the characteristics of security bugs.
机译:安全性错误可以灾难性地影响我们越来越数码的生活。设计用于检测和修复软件安全错误的有效工具需要深入了解安全错误特征。在本文中,我们进行了一个对安全漏洞的综合研究,并提出了分类标准安全性错误类别,即根本原因,后果和位置。另外,我们从五个项目中选择的1076个错误报告(即,Apache Tomcat,Apache HTTP服务器,Mozilla Firefox,Linux内核和Eclipse)在NVD进行调查中。最后,我们调查了分类结果与课程之间的相关性获得了一些发现:(1)内存操作是最常见的安全错误;(2)安全错误的主要根原因是CON(配置错误),INP(输入验证错误)和MEM(内存错误); (3)超过40%的严重程度安全错误很高; (4)INP引起的安全错误主要发生在Web上;和(5)日志(逻辑资源错误)引起的安全错误通常导致DOS(拒绝服务)。我们通过数据分析讨论了这些发现,也可以提供帮助开发人员更好地了解安全错误的特征。

著录项

  • 来源
    《Journal of software: evolution and process》 |2021年第10期|e2376.1-e2376.22|共22页
  • 作者单位

    School of Information Engineering YangzhouUniversity Yangzhou China;

    School of Information Engineering YangzhouUniversity Yangzhou China State Key Laboratory for Novel SoftwareTechnology Nanjing University Nanjing China;

    School of Information Engineering YangzhouUniversity Yangzhou China State Key Laboratory for Novel SoftwareTechnology Nanjing University Nanjing China Key Laboratory of Safety-Critical SoftwareMinistry of Industry and InformationTechnology Nanjing University of Aeronauticsand Astronautics Nanjing China;

    School of Information Engineering YangzhouUniversity Yangzhou China;

    Faculty of Information Technology MonashUniversity Melbourne Australia;

    School of Information Engineering YangzhouUniversity Yangzhou China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    bug characteristics; empirical study; security bugs;

    机译:错误特征;实证研究;安全错误;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号