Vulnerability Discovery in Open- and Closed-Source Software: A New Paradigm

被引:4
|
作者
Sharma, Ruchi [1 ]
Singh, R. K. [1 ]
机构
[1] Indira Gandhi Delhi Tech Univ Women, Dept Informat Technol, Delhi, India
来源
关键词
Vulnerability discovery; Open source; Closed source; Gamma; Alhazmi-Malaiya logistic model;
D O I
10.1007/978-981-10-8848-3_51
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
For assisting the developers in process of software development, vulnerability discovery models were developed by researchers which helped in discovering the vulnerabilities with time. These models facilitate the developers in patch management while providing assistance in optimal resource allocation and assessing associated security risks. Among the existing models for vulnerability discovery, Alhazmi-Malaiya logistic model is considered the best-fitted model on all kinds of datasets owing to its ability to capture s-shaped nature of the curves. But, it has the limitation of dependence on shape of dataset. We have proposed a new model that is shape-independent accounting for better goodness of fit as compared to the earlier VDM. The proposed model and Alhazmi-Malaiya logistic model for vulnerability discovery has been evaluated on three real-life datasets each for open-and closed-source software, and the results are presented toward the end of the paper.
引用
收藏
页码:533 / 539
页数:7
相关论文
共 50 条
  • [1] Enabling Mutant Generation for Open- and Closed-Source Android Apps
    Escobar-Velasquez, Camilo
    Linares-Vasquez, Mario
    Bavota, Gabriele
    Tufano, Michele
    Moran, Kevin
    Di Penta, Massimiliano
    Vendome, Christopher
    Bernal-Cardenas, Carlos
    Poshyvanyk, Denys
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2022, 48 (01) : 186 - 208
  • [2] Features of the Licensing of Open-Source and Closed-Source Software
    Pivneva, Svetlana, V
    Vitkovskaya, Nataliaya G.
    Katys, Petr
    Goncharov, Vitaly V.
    Livson, Maya
    [J]. REVISTA GEINTEC-GESTAO INOVACAO E TECNOLOGIAS, 2021, 11 (02): : 1211 - 1221
  • [3] Balanced knowledge distribution among software development teams-Observations from open- and closed-source software development
    Shafiq, Saad
    Mayr-Dorn, Christoph
    Mashkoor, Atif
    Egyed, Alexander
    [J]. JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2024, 36 (08)
  • [4] An empirical study of open-source and closed-source software products
    Paulson, JW
    Succi, G
    Eberlein, A
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2004, 30 (04) : 246 - 256
  • [5] Detecting Interpersonal Conflict in Issues and Code Review: Cross Pollinating Open- and Closed-Source Approaches
    Qiu, Huilian Sophie
    Vasilescu, Bogdan
    Kastner, Christian
    Egelman, Carolyn
    Jaspan, Ciera
    Murphy-Hill, Emerson
    [J]. 2022 ACM/IEEE 44TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: SOFTWARE ENGINEERING IN SOCIETY (ICSE-SEIS 2022), 2022, : 41 - 55
  • [6] ONCE: Boosting Content-based Recommendation with Both Open- and Closed-source Large Language Models
    Liu, Qijiong
    Chen, Nuo
    Sakai, Tetsuya
    Wu, Xiao-Ming
    [J]. PROCEEDINGS OF THE 17TH ACM INTERNATIONAL CONFERENCE ON WEB SEARCH AND DATA MINING, WSDM 2024, 2024, : 452 - 461
  • [7] Testing the theory of relative defect proneness for closed-source software
    Gunes Koru
    Hongfang Liu
    Dongsong Zhang
    Khaled El Emam
    [J]. Empirical Software Engineering, 2010, 15 : 577 - 598
  • [8] Testing the theory of relative defect proneness for closed-source software
    Koru, Gunes
    Liu, Hongfang
    Zhang, Dongsong
    El Emam, Khaled
    [J]. EMPIRICAL SOFTWARE ENGINEERING, 2010, 15 (06) : 577 - 598
  • [9] Exorcist: Automated Differential Analysis to Detect Compromises in Closed-Source Software Supply Chains
    Barr-Smith, Frederick
    Blazytko, Tim
    Baker, Richard
    Martinovic, Ivan
    [J]. PROCEEDINGS OF THE 2022 ACM WORKSHOP ON SOFTWARE SUPPLY CHAIN OFFENSIVE RESEARCH AND ECOSYSTEM DEFENSES, SCORED 2022, 2022, : 51 - 61
  • [10] Open Source Textbooks: A Paradigm Derived from Open Source Software
    Bergman, Seth D.
    [J]. PUBLISHING RESEARCH QUARTERLY, 2014, 30 (01) : 1 - 10