Title : 
Application of Vulnerability Discovery Models to Major Operating Systems
         
        
            Author : 
Alhazmi, Omar H. ; Malaiya, Yashwant K.
         
        
            Author_Institution : 
Colorado State Univ., Fort Collins
         
        
        
        
        
            fDate : 
3/1/2008 12:00:00 AM
         
        
        
        
            Abstract : 
A number of security vulnerabilities have been reported in the Windows, and Linux operating systems. Both the developers, and users of operating systems have to utilize significant resources to evaluate, and mitigate the risk posed by these vulnerabilities. Vulnerabilities are discovered throughout the life of a software system by both the developers, and external testers. Vulnerability discovery models are needed that describe the vulnerability discovery process for determining readiness for release, future resource allocation for patch development, and evaluating the risk of vulnerability exploitation. Here, we analytically describe six models that have been recently proposed, and evaluate those using actual data for four major operating systems. The applicability of the proposed models, and the significance of the parameters involved are examined. The results show that some of the models tend to capture the discovery process better than others.
         
        
            Keywords : 
Linux; resource allocation; security of data; software reliability; Linux operating systems; Windows; operating systems; patch development; resource allocation; security vulnerabilities; software system; vulnerability discovery models; Operating systems; security; software reliability growth models; vulnerabilities; vulnerability discovery;
         
        
        
            Journal_Title : 
Reliability, IEEE Transactions on
         
        
        
        
        
            DOI : 
10.1109/TR.2008.916872