Title :
Mining Bug Databases for Unidentified Software Vulnerabilities
Author :
Wijayasekara, Dumidu ; Manic, Milos ; Wright, Jason L. ; McQueen, Miles
Author_Institution :
Univ. of Idaho, Idaho Falls, ID, USA
Abstract :
Identifying software vulnerabilities is becoming more important as critical and sensitive systems increasingly rely on complex software systems. It has been suggested in previous work that some bugs are only identified as vulnerabilities long after the bug has been made public. These vulnerabilities are known as hidden impact vulnerabilities. This paper discusses existing bug data mining classifiers and present an analysis of vulnerability databases showing the necessity to mine common publicly available bug databases for hidden impact vulnerabilities. We present a vulnerability analysis from January 2006 to April 2011 for two well known software packages: Linux kernel and MySQL. We show that 32% (Linux) and 62% (MySQL) of vulnerabilities discovered in this time period were hidden impact vulnerabilities. We also show that the percentage of hidden impact vulnerabilities has increased from 25% to 36% in Linux and from 59% to 65% in MySQL in the last two years. We then propose a hidden impact vulnerability identification methodology based on text mining classifier for bug databases. Finally, we discuss potential challenges faced by a development team when using such a classifier.
Keywords :
Linux; SQL; data mining; database management systems; pattern classification; program debugging; software packages; text analysis; Linux kernel; MySQL; bug data mining classifiers; bug database mining; complex software systems; hidden impact vulnerability identification methodology; software packages; text mining classifier; unidentified software vulnerabilities; vulnerability database analysis; Computer bugs; Data mining; Databases; Delay; Kernel; Linux; Bug database mining; Classifier; Hidden impact vulnerabilities; Vulnerability discovery;
Conference_Titel :
Human System Interactions (HSI), 2012 5th International Conference on
Conference_Location :
Perth, WA
Print_ISBN :
978-1-4673-4498-2
DOI :
10.1109/HSI.2012.22