arrow
Return

Does OpenBSD and Firefox's Security Improve With Time?

delete2023-07-01
delete0
PRE
AI
J
Jian Shi
D
Deqing Zou *
S
Shouhuai Xu
X
Xianjun Deng
金海 (Hai Jin)
DOI:10.1109/TDSC.2022.3153325delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Ozment and Schechter (USENIX Security'2006) analyzed the evolution of OpenBSD vulnerabilities over the span of 7 years (1998-2005) and concluded that its security increases with age. In this paper, we extend their study by analyzing the evolution of OpenBSD vulnerabilities over the span of 22 years (1998-2020) and Firefox vulnerabilities over the span of 9 years (2011-2020). Our empirical study leads to a number of insights, including the following: both OpenBSD and Firefox get more secure (i.e., less vulnerable) with time, but today's developers do not necessarily produce more secure code; OpenBSD and Firefox developers tend to make similar security mistakes, but Firefox vulnerabilities are easier to exploit; finally, Firefox's vulnerability density is almost one order of magnitude higher than OpenBSD's, meaning Firefox is more vulnerable.
Keywords:
Dependability
security
vulnerability
vulnerability metric

Journal

IEEE Transactions on Dependable and Secure Computing cover
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
Papers:
2.4K
Citations:
9.6K

Organization

U
university of colorado at colorado springs
Scholars:
691
Papers: 602
Citations: 2
University of Colorado System cover
University of Colorado System
Scholars:
6.3W
Papers: 5.5W
Citations: 1.8K