DocumentCode
55577
Title
An Empirical Methodology to Evaluate Vulnerability Discovery Models
Author
Massacci, F. ; Viet Hung Nguyen
Author_Institution
DISI, Univ. of Trento, Trento, Italy
Volume
40
Issue
12
fYear
2014
fDate
Dec. 1 2014
Firstpage
1147
Lastpage
1162
Abstract
Vulnerability discovery models (VDMs) operate on known vulnerability data to estimate the total number of vulnerabilities that will be reported after a software is released. VDMs have been proposed by industry and academia, but there has been no systematic independent evaluation by researchers who are not model proponents. Moreover, the traditional evaluation methodology has some issues that biased previous studies in the field. In this work we propose an empirical methodology that systematically evaluates the performance of VDMs along two dimensions (quality and predictability) and addresses all identified issues of the traditional methodology. We conduct an experiment to evaluate most existing VDMs on popular web browsers´ vulnerability data. Our comparison shows that the results obtained by the proposed methodology are more informative than those by the traditional methodology. Among evaluated VDMs, the simplest linear model is the most appropriate choice in terms of both quality and predictability for the first 6-12 months since a release date. Otherwise, logistics-based models are better choices.
Keywords
online front-ends; security of data; software quality; VDM; Web browser vulnerability data; empirical methodology; logistics-based model; predictability; quality; time 6 month to 12 month; vulnerability discovery model evaluation; Browsers; Computer bugs; Computer security; Data models; Operating systems; Predictive models; Software security; empirical evaluation; vulnerability analysis; vulnerability discovery model;
fLanguage
English
Journal_Title
Software Engineering, IEEE Transactions on
Publisher
ieee
ISSN
0098-5589
Type
jour
DOI
10.1109/TSE.2014.2354037
Filename
6891367
Link To Document