DocumentCode :
2128661
Title :
Estimating Software Vulnerabilities: A Case Study Based on the Misclassification of Bugs in MySQL Server
Author :
Wright, Jason L. ; Larsen, Jason W. ; McQueen, Miles
Author_Institution :
Cyber Security R&D, Idaho Nat. Lab., Idaho Falls, ID, USA
fYear :
2013
fDate :
2-6 Sept. 2013
Firstpage :
72
Lastpage :
81
Abstract :
Software vulnerabilities are an important part of the modern software economy. Being able to accurately classify software defects as a vulnerability, or not, allows developers and end users to expend appropriately more effort on fixing those defects which have security implications. However, we demonstrate in this paper that the expected number of misclassified bugs (those not marked as also being vulnerabilities) may be quite high and thus human efforts to classify bug reports as vulnerabilities appears to be quite ineffective. We conducted an experiment using the MySQL bug report database to estimate the number of misclassified bugs yet to be identified as vulnerabilities. The MySQL database server versions we evaluated currently have 76 publicly reported vulnerabilities. Yet our experimental results show, with 95% confidence, that the MySQL bug database has between 499 and 587 misclassified bugs for the same software. This is an estimated increase of vulnerabilities between657% and 772% over the number currently identified and publicly reported in the National Vulnerability Database and the Open Source Vulnerability Database.
Keywords :
SQL; program debugging; relational databases; software reliability; MySQL bug report database; MySQL server; bug misclassification; national vulnerability database; open source vulnerability database; software vulnerability estimation; Computer bugs; Databases; Security; Servers; Sociology; Software; Statistics; bug reports; misclassification; software vulnerabilities; vulnerability estimation;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Availability, Reliability and Security (ARES), 2013 Eighth International Conference on
Conference_Location :
Regensburg
Type :
conf
DOI :
10.1109/ARES.2013.14
Filename :
6657228
Link To Document :
بازگشت