返回
Evaluating Complexity, Code Churn, and Developer Activity Metrics as Indicators of Software Vulnerabilities
DOI:10.1109/TSE.2010.81.png)
摘要
En 中文
Security inspection and testing require experts in security who think like an attacker. Security experts need to know code locations on which to focus their testing and inspection efforts. Since vulnerabilities are rare occurrences, locating vulnerable code locations can be a challenging task. We investigated whether software metrics obtained from source code and development history are discriminative and predictive of vulnerable code locations. If so, security experts can use this prediction to prioritize security inspection and testing efforts. The metrics we investigated fall into three categories: complexity, code churn, and developer activity metrics. We performed two empirical case studies on large, widely used open-source projects: the Mozilla Firefox web browser and the Red Hat Enterprise Linux kernel. The results indicate that 24 of the 28 metrics collected are discriminative of vulnerabilities for both projects. The models using all three types of metrics together predicted over 80 percent of the known vulnerable files with less than 25 percent false positives for both projects. Compared to a random selection of files for inspection and testing, these models would have reduced the number of files and the number of lines of code to inspect or test by over 71 and 28 percent, respectively, for both projects.
Keyword:
Fault prediction
software metrics
software security
vulnerability prediction
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
5.6
论文数:
2.8K
被引数:
1.1W
机构
引用论文
A study on the anti-tumor mechanism of total flavonoids from Radix Tetrastigmae against additional cell line based on COX-2-mediated Wnt/β-catenin signaling pathway基于COX-2介导的Wnt/β-catenin信号通路研究柴草总黄酮 对其他细胞系的抗肿瘤机制
Oncotarget
IF0
Controlled partial embedding of carbon nanotubes within flexible transparent layers碳纳米管在柔性透明层内的受控部分嵌入

