• DocumentCode
    2534690
  • Title

    Searching for a Needle in a Haystack: Predicting Security Vulnerabilities for Windows Vista

  • Author

    Zimmermann, Thomas ; Nagappan, Nachiappan ; Williams, Laurie

  • Author_Institution
    Microsoft Res., Redmond, WA, USA
  • fYear
    2010
  • fDate
    6-10 April 2010
  • Firstpage
    421
  • Lastpage
    428
  • Abstract
    Many factors are believed to increase the vulnerability of software system; for example, the more widely deployed or popular is a software system the more likely it is to be attacked. Early identification of defects has been a widely investigated topic in software engineering research. Early identification of software vulnerabilities can help mitigate these attacks to a large degree by focusing better security verification efforts in these components. Predicting vulnerabilities is complicated by the fact that vulnerabilities are, most often, few in number and introduce significant bias by creating a sparse dataset in the population. As a result, vulnerability prediction can be thought of us preverbally “searching for a needle in a haystack.” In this paper, we present a large-scale empirical study on Windows Vista, where we empirically evaluate the efficacy of classical metrics like complexity, churn, coverage, dependency measures, and organizational structure of the company to predict vulnerabilities and assess how well these software measures correlate with vulnerabilities. We observed in our experiments that classical software measures predict vulnerabilities with a high precision but low recall values. The actual dependencies, however, predict vulnerabilities with a lower precision but substantially higher recall.
  • Keywords
    operating systems (computers); research and development; security of data; software metrics; Windows Vista; security verification; security vulnerability prediction; software engineering research; software metrics; software system vulnerability; Computer science; Computer security; Data security; Databases; Needles; Open source software; Software engineering; Software measurement; Software systems; Software testing; Churn; Complexity; Coverage; Dependencies; Metrics; Organizational Structure; Prediction; Vulnerabilities;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Testing, Verification and Validation (ICST), 2010 Third International Conference on
  • Conference_Location
    Paris
  • Print_ISBN
    978-1-4244-6435-7
  • Type

    conf

  • DOI
    10.1109/ICST.2010.32
  • Filename
    5477059