首页> 美国政府科技报告 >Estimating Software Vulnerabilities: A Case Study Based on the Misclassification of Bugs in MySQL Server, 8th International Conference on Availability, Reliability, and Security (ARES 2013).
【24h】

Estimating Software Vulnerabilities: A Case Study Based on the Misclassification of Bugs in MySQL Server, 8th International Conference on Availability, Reliability, and Security (ARES 2013).

机译:估计软件漏洞:基于mysQL服务器中错误的错误分类的案例研究,第8届可用性,可靠性和安全性国际会议(aREs 2013)。

获取原文

摘要

Software vulnerabilities are an important part of the modern software economy. Being able to accurately classify software defects as a vulnerability, or not, allows developers and end users to expend appropriately more effort on fixing those defects which have security implications. However, we demonstrate in this paper that the expected number of misclassified bugs (those not marked as also being vulnerabilities) may be quite high and thus human efforts to classify bug reports as vulnerabilities appears to be quite ineffective. We conducted an experiment using the MySQL bug report database to estimate the number of misclassified bugs yet to be identified as vulnerabilities. The MySQL database server versions we evaluated currently have 76 publicly reported vulnerabilities. Yet our experimental results show, with 95% confidence, that the MySQL bug database has between 499 and 587 misclassified bugs for the same software. This is an estimated increase of vulnerabilities between 657% and 772% over the number currently identified and publicly reported in the National Vulnerability Database and the Open Source Vulnerability Database.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号