Using Software Reliability Models for Security Assessment - Verification of Assumptions

被引:0
|
作者
Lee, Da Young [1 ]
Vouk, Mladen [1 ]
Williams, Laurie [1 ]
机构
[1] N Carolina State Univ, Dept Comp Sci, Raleigh, NC 27695 USA
关键词
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Can software reliability models be used to assess software security? One of the issues is that security problems are relatively rare under "normal" operational profiles, while "classical" reliability models may not be suitable for use in attack conditions. We investigated a range of Fedora open source software security problems to see if some of the basic assumptions behind software reliability growth models hold for discovery of security problems in non-attack situations. We find that in some cases, under "normal" operational use, security problem detection process may be described as a Poisson process. In those cases, we can use appropriate classical software reliability growth models to assess "security reliability" of that software in non-attack situations.
引用
收藏
页码:23 / 24
页数:2
相关论文
共 50 条
  • [1] The method of software reliability growth models choice using assumptions matrix
    Kharchenko, VS
    Tarasyuk, OM
    Sklyar, VV
    Dubnitsky, VY
    26TH ANNUAL INTERNATIONAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE, PROCEEDINGS, 2002, : 541 - 546
  • [2] SOFTWARE-RELIABILITY MODELS - ASSUMPTIONS, LIMITATIONS, AND APPLICABILITY
    GOEL, AL
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 1985, 11 (12) : 1411 - 1423
  • [3] Software reliability growth models: Assumptions vs. reality
    Wood, A
    EIGHTH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING, PROCEEDINGS, 1997, : 136 - 141
  • [4] Applying software reliability models on security incidents
    Condon, Edward
    Cukier, Michel
    He, Tao
    ISSRE 2007: 18TH IEEE INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING, PROCEEDINGS, 2007, : 159 - 168
  • [5] ASSESSMENT OF SOFTWARE-RELIABILITY MODELS
    TROY, R
    MOAWAD, R
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 1985, 11 (09) : 839 - 849
  • [6] The Comparison of Software Reliability Assessment Models
    Cristescu, Marian Pompiliu
    Stoica, Eduard Alexandru
    Ciovica, Laurentiu Vasile
    22ND INTERNATIONAL ECONOMIC CONFERENCE OF SIBIU 2015, IECS 2015 ECONOMIC PROSPECTS IN THE CONTEXT OF GROWING GLOBAL AND REGIONAL INTERDEPENDENCIES, 2015, 27 : 669 - 675
  • [7] Combining testing and correctness verification in software reliability assessment
    Cukic, B
    1997 HIGH-ASSURANCE ENGINEERING WORKSHOP - PROCEEDINGS, 1997, : 182 - 187
  • [8] Software security is software reliability
    Lindner, Felix FX
    COMMUNICATIONS OF THE ACM, 2006, 49 (06) : 57 - 61
  • [9] Quantitative assessment models for software safety/reliability
    Yamada, S
    Tokuno, K
    Kasano, Y
    ELECTRONICS AND COMMUNICATIONS IN JAPAN PART II-ELECTRONICS, 1998, 81 (05): : 33 - 43
  • [10] Quantitative assessment models for software safety/reliability
    Tottori Univ, Tottori, Japan
    Electron Commun Jpn Part II Electron, 5 (33-43):