A hierarchical model for quantifying software security based on static analysis alerts and software metrics

被引:13
|
作者
Siavvas, Miltiadis [1 ,2 ]
Kehagias, Dionysios [2 ]
Tzovaras, Dimitrios [2 ]
Gelenbe, Erol [1 ,3 ]
机构
[1] Imperial Coll London, London SW7 2AZ, England
[2] Ctr Res & Technol Hellas, Thessaloniki, Greece
[3] Polish Acad Sci, Inst Theoret & Appl Informat, Ul Baltycka 5, PL-44100 Gliwice, Poland
基金
欧盟地平线“2020”;
关键词
Software Security; Software Quality Evaluation; Security Assessment; VULNERABILITIES; COMPLEXITY; DESIGN; TOOLS; BUGS;
D O I
10.1007/s11219-021-09555-0
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Despite the acknowledged importance of quantitative security assessment in secure software development, current literature still lacks an efficient model for measuring internal software security risk. To this end, in this paper, we introduce a hierarchical security assessment model (SAM), able to assess the internal security level of software products based on low-level indicators, i.e., security-relevant static analysis alerts and software metrics. The model, following the guidelines of ISO/IEC 25010, and based on a set of thresholds and weights, systematically aggregates these low-level indicators in order to produce a high-level security score that reflects the internal security level of the analyzed software. The proposed model is practical, since it is fully automated and operationalized in the form of a standalone tool and as part of a broader Computer-Aided Software Engineering (CASE) platform. In order to enhance its reliability, the thresholds of the model were calibrated based on a repository of 100 popular software applications retrieved from Maven Repository. Furthermore, its weights were elicited in a way to chiefly reflect the knowledge expressed by the Common Weakness Enumeration (CWE), through a novel weights elicitation approach grounded on popular decision-making techniques. The proposed model was evaluated on a large repository of 150 open-source software applications retrieved from GitHub and 1200 classes retrieved from the OWASP Benchmark. The results of the experiments revealed the capacity of the proposed model to reliably assess internal security at both product level and class level of granularity, with sufficient discretion power. They also provide preliminary evidence for the ability of the model to be used as the basis for vulnerability prediction. To the best of our knowledge, this is the first fully automated, operationalized and sufficiently evaluated security assessment model in the modern literature.
引用
收藏
页码:431 / 507
页数:77
相关论文
共 50 条
  • [1] A hierarchical model for quantifying software security based on static analysis alerts and software metrics
    Miltiadis Siavvas
    Dionysios Kehagias
    Dimitrios Tzovaras
    Erol Gelenbe
    [J]. Software Quality Journal, 2021, 29 : 431 - 507
  • [2] Software Security Static Analysis False Alerts Handling Approaches
    Akremi, Aymen
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (11) : 702 - 711
  • [3] Machine Learning to Combine Static Analysis Alerts with Software Metrics to Detect Security Vulnerabilities: An Empirical Study
    Pereira, Jose D'Abruzzo
    Campos, Joao R.
    Vieira, Marco
    [J]. 2021 17TH EUROPEAN DEPENDABLE COMPUTING CONFERENCE (EDCC 2021), 2021, : 1 - 8
  • [4] A stake holder based model for software security metrics
    Sree Ram Kumar, T.
    Alagarsamy, K.
    [J]. International Journal of Computer Science Issues, 2011, 8 (02): : 444 - 448
  • [5] Software Metrics in Static Program Analysis
    Vogelsang, Andreas
    Fehnker, Ansgar
    Huuck, Ralf
    Reif, Wolfgang
    [J]. FORMAL METHODS AND SOFTWARE ENGINEERING, 2010, 6447 : 485 - +
  • [6] Design and analysis of hierarchical software metrics
    Prather, RE
    [J]. ACM COMPUTING SURVEYS, 1995, 27 (04) : 497 - 518
  • [7] Design and analysis of hierarchical software metrics
    [J]. ACM Comput Surv, 4 (497):
  • [8] ON HIERARCHICAL SOFTWARE METRICS
    PRATHER, RE
    [J]. SOFTWARE ENGINEERING JOURNAL, 1987, 2 (02): : 42 - 45
  • [9] Static and dynamic complexity analysis of software metrics
    Kaur, Kamaljit
    Minhas, Kirti
    Mehan, Neha
    Kakkar, Namita
    [J]. World Academy of Science, Engineering and Technology, 2009, 56 : 159 - 161
  • [10] Evaluation of Static Analysis Tools for Software Security
    AlBreiki, Hamda Hasan
    Mahmoud, Qusay H.
    [J]. 2014 10TH INTERNATIONAL CONFERENCE ON INNOVATIONS IN INFORMATION TECHNOLOGY (IIT), 2014, : 93 - 98