• DocumentCode
    55577
  • Title

    An Empirical Methodology to Evaluate Vulnerability Discovery Models

  • Author

    Massacci, F. ; Viet Hung Nguyen

  • Author_Institution
    DISI, Univ. of Trento, Trento, Italy
  • Volume
    40
  • Issue
    12
  • fYear
    2014
  • fDate
    Dec. 1 2014
  • Firstpage
    1147
  • Lastpage
    1162
  • Abstract
    Vulnerability discovery models (VDMs) operate on known vulnerability data to estimate the total number of vulnerabilities that will be reported after a software is released. VDMs have been proposed by industry and academia, but there has been no systematic independent evaluation by researchers who are not model proponents. Moreover, the traditional evaluation methodology has some issues that biased previous studies in the field. In this work we propose an empirical methodology that systematically evaluates the performance of VDMs along two dimensions (quality and predictability) and addresses all identified issues of the traditional methodology. We conduct an experiment to evaluate most existing VDMs on popular web browsers´ vulnerability data. Our comparison shows that the results obtained by the proposed methodology are more informative than those by the traditional methodology. Among evaluated VDMs, the simplest linear model is the most appropriate choice in terms of both quality and predictability for the first 6-12 months since a release date. Otherwise, logistics-based models are better choices.
  • Keywords
    online front-ends; security of data; software quality; VDM; Web browser vulnerability data; empirical methodology; logistics-based model; predictability; quality; time 6 month to 12 month; vulnerability discovery model evaluation; Browsers; Computer bugs; Computer security; Data models; Operating systems; Predictive models; Software security; empirical evaluation; vulnerability analysis; vulnerability discovery model;
  • fLanguage
    English
  • Journal_Title
    Software Engineering, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    0098-5589
  • Type

    jour

  • DOI
    10.1109/TSE.2014.2354037
  • Filename
    6891367