An empirical study of vulnerability discovery methods over the past ten years

被引:6
|
作者
Cui, Lei [1 ]
Cui, Jiancong
Hao, Zhiyu [1 ,2 ]
Li, Lun [1 ]
Ding, Zhenquan [1 ]
Liu, Yongji [1 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing 100093, Peoples R China
[2] Univ Chinese Acad Sci, Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
Vulnerability discovery; Empirical study; Effectiveness com parison; Vulnerability; Vulnerability detection; Vulnerability analysis;
D O I
10.1016/j.cose.2022.102817
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, hundreds of vulnerability discovery methods have been proposed and proven to be effective (i.e., Is Effective) by discovering thousands of vulnerabilities in real-world programs. However, the quantified ability to indicate how effective (i.e., How Effective) a method is still unknown. In this paper, we perform an empirical study to understand the effectiveness of these methods better. More specifically, we prepare a dataset of 124 papers focusing on vulnerability discovery from S&P, SECURITY, CCS, and NDSS over the past ten years. These papers cover four techniques, including static analysis, dynamic analysis, concolic analysis, and fuzzing, yielding 3970 vulnerabilities, of which 954 get CVE records. Then, we extract several attributes from the paper and categorize them into five dimensions, i.e., popularity, scalability, capability, severity, and diversity, which facilitate us to compare various techniques along these dimensions statistically. Moreover, taking these attributes into account, we propose a scoring method to quantify the effectiveness of a method, thereby indicating how effective a method is. The empirical study on dimensions and effectiveness scores reveals several findings that help better understand the effectiveness of vulnerability discovery techniques.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] An Empirical Study of Web Vulnerability Discovery Ecosystems
    Zhao, Mingyi
    Grossklags, Jens
    Liu, Peng
    CCS'15: PROCEEDINGS OF THE 22ND ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2015, : 1105 - 1117
  • [2] MARINE BOILER DEVELOPMENT OVER THE PAST TEN YEARS.
    Hodgkin, A.F.
    1600, (85 Ser A):
  • [3] ABCDE: Past ten years, next ten years
    Fischer, S
    ANNUAL WORLD BANK CONFERENCE ON DEVELOPMENT ECONOMICS 1998, 1999, : 77 - 86
  • [4] Stroke Epidemiology in China over the Past Ten Years, a Study on Subtype Distribution and Case Fatality
    Yan, Lei
    Lu, Jiapeng
    Cui, Yadong
    Ramey, Dena R.
    Li, Jing
    Jiang, Lixin
    PHARMACOEPIDEMIOLOGY AND DRUG SAFETY, 2014, 23 : 376 - 377
  • [5] A Study on Transportation System in China in the Past Ten Years
    Guo Ruijun
    Wang Wanxiang
    EBM 2010: INTERNATIONAL CONFERENCE ON ENGINEERING AND BUSINESS MANAGEMENT, VOLS 1-8, 2010, : 3138 - 3143
  • [6] An Investigation of Corpus Contributions to Lexicographic Challenges over the Past Ten Years
    Abdelzaher, Esra M.
    LEXIKOS, 2022, 32 : 162 - 179
  • [7] The analysis of the investment climate in Chongqing municipality over the past ten years
    Ye Xiaosu
    Li Yanyan
    PROCEEDINGS OF CRIOCM 2007 INTERNATIONAL RESEARCH SYMPOSIUM ON ADVANCEMENT OF CONSTRUCTION MANAGEMENT AND REAL ESTATE, VOLS 1 AND 2, 2007, : 165 - 174
  • [9] Ten years past the Post
    Lakhtakia, A
    COMPLEX MEDIUMS V: LIGHT AND COMPLEXITY, 2004, 5508 : 85 - 94
  • [10] The empirical trend Ten years on
    Sampson, Geoffrey
    INTERNATIONAL JOURNAL OF CORPUS LINGUISTICS, 2013, 18 (02) : 281 - 289