earticle

논문검색

Evaluating Software Metrics as Predictors of Software Vulnerabilities

초록

영어

Web application security is an important problem in today’s Internet. A major cause of this is that many developers are not equipped with the right skills to develop secure code. Because of limited time and resources, web engineers need help in recognizing vulnerable components. A useful approach to predict vulnerable code would allow them to prioritize security-auditing efforts. In this work, we compare the performance of different classification techniques in predicting vulnerable PHP files and propose an application of these classification rules. We performed empirical case studies on three large open source web-projects. Software metrics are investigated whether they are discriminative and predictive of vulnerable code, and can guide actions for improvement of code and development team and can prioritize validation and verification efforts. The results indicate that the metrics are discriminative and predictive of vulnerabilities.

목차

Abstract
 1. Introduction
 2. Software Metrics
 3. Approach
 4. Experimental Evaluation
  4.1. Data Set
  4.2. Classifiers
  4.3. Evaluation Metrics
  4.4. Results
 5. Application
 6. Threats to Validity
 7. Related Work
  7.1. Fault Prediction
  7.2. Vulnerability prediction
  7.3. Equations
 8. Conclusion
 References

저자정보

  • Mamdouh Alenezi College of Computer & Information Sciences, Prince Sultan University Riyadh, Saudi Arabia
  • Ibrahim Abunadi College of Computer & Information Sciences, Prince Sultan University Riyadh, Saudi Arabia

참고문헌

자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

      0개의 논문이 장바구니에 담겼습니다.