首页> 外文期刊>Quality and Reliability Engineering International >Coverage-based vulnerability discovery modeling to optimize disclosure time using multiattribute approach
【24h】

Coverage-based vulnerability discovery modeling to optimize disclosure time using multiattribute approach

机译:基于覆盖的漏洞发现建模,可使用多属性方法优化披露时间

获取原文
获取原文并翻译 | 示例
       

摘要

Software vulnerabilities trend over time has been proposed by various researchers and academicians in recent years. But none of them have considered operational coverage function in vulnerability discovery modeling. In this research paper, we have proposed a generalized statistical model that determines the relationship between operational coverage function and the number of expected vulnerabilities. During the operational phase, possible vulnerable sites are covered and vulnerabilities present at a particular site are discovered with some probability. We have assumed that the proposed model follows the nonhomogeneous Poisson process properties; thus, different distributions are used to formulate the model. The numerical illustration shows that the proposed model performs better and has the good fitness to the Google Chrome data. The second focus of this research paper is to evaluate the total cost incurred by the developer after software release and to identify the optimal vulnerability disclosure time through multiobjective utility function. The proposed vulnerability discovery helps in optimization. The optimal time problem depends on the combined effect of cost, risk, and effort.
机译:近年来,各种研究人员和院士提出了软件漏洞随时间的趋势。但是他们都没有考虑漏洞发现建模中的操作覆盖功能。在这篇研究论文中,我们提出了一种通用的统计模型,该模型确定了操作覆盖率函数和预期漏洞数量之间的关系。在运营阶段,可能的易受攻击的站点将被覆盖,并以一定的概率发现特定站点上存在的漏洞。我们假设所提出的模型遵循非均匀的泊松过程性质。因此,使用不同的分布来建立模型。数值插图表明,所提出的模型性能更好,并且对Google Chrome数据具有良好的适应性。本研究报告的第二个重点是评估开发人员在软件发布后产生的总成本,并通过多目标效用函数确定最佳漏洞披露时间。建议的漏洞发现有助于优化。最佳时间问题取决于成本,风险和工作量的综合影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号