首页> 外文OA文献 >A Systematically Empirical Evaluation of Vulnerability Discovery Models: a Study on Browsers' Vulnerabilities
【2h】

A Systematically Empirical Evaluation of Vulnerability Discovery Models: a Study on Browsers' Vulnerabilities

机译:漏洞发现模型的系统经验评估:   关于浏览器漏洞的研究

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

A precise vulnerability discovery model (VDM) will provide a useful insightto assess software security, and could be a good prediction instrument for bothsoftware vendors and users to understand security trends and plan aheadpatching schedule accordingly. Thus far, several models have been proposed andvalidated. Yet, no systematically independent validation by somebody other thanthe author exists. Furthermore, there are a number of issues that might biasprevious studies in the field. In this work, we fill in the gap by introducingan empirical methodology that systematically evaluates the performance of a VDMin two aspects: quality and predictability. We further apply this methodologyto assess existing VDMs. The results show that some models should be rejectedoutright, while some others might be adequate to capture the discovery processof vulnerabilities. We also consider different usage scenarios of VDMs and findthat the simplest linear model is the most appropriate choice in terms of bothquality and predictability when browsers are young. Otherwise, logistics-basedmodels are better choices.
机译:精确的漏洞发现模型(VDM)将为评估软件安全性提供有用的见解,并且可以成为软件供应商和用户了解安全趋势并据此计划提前修补计划的良好预测工具。到目前为止,已经提出并验证了几种模型。但是,除作者以外,没有人进行系统独立的验证。此外,还有许多问题可能会使该领域以前的研究产生偏差。在这项工作中,我们通过引入一种经验方法来填补空白,该方法从两个方面系统地评估VDM的性能:质量和可预测性。我们进一步将这种方法应用于评估现有的VDM。结果表明,应该完全拒绝某些模型,而另一些模型可能足以捕获漏洞的发现过程。我们还考虑了VDM的不同使用场景,并且发现最简单的线性模型在浏览器年轻时就质量和可预测性而言是最合适的选择。否则,基于物流的模型是更好的选择。

著录项

  • 作者单位
  • 年度 2013
  • 总页数
  • 原文格式 PDF
  • 正文语种 {"code":"en","name":"English","id":9}
  • 中图分类
  • 入库时间 2022-08-20 21:09:31

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号