کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
458113 696106 2013 12 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Analyses of two end-user software vulnerability exposure metrics (extended version)
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
Analyses of two end-user software vulnerability exposure metrics (extended version)
چکیده انگلیسی

Understanding the exposure risk of software vulnerabilities is an important part of the software ecosystem. Reliable software vulnerability metrics allow end-users to make informed decisions regarding the risk posed by the choice of one software package versus another. In this article, we develop and analyze two new security metrics: median active vulnerabilities (MAV) and vulnerability free days (VFD). Both metrics take into account both the rate of vulnerability discovery and the rate at which vendors produce corresponding patches. We examine how our metrics are computed from publicly available data sets and then demonstrate their use in a case study with various vendors and products. Finally, we discuss the use of the metrics by various software stakeholders and how end-users can benefit from their use.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Information Security Technical Report - Volume 17, Issue 4, May 2013, Pages 173–184
نویسندگان
, , ,