• DocumentCode
    2128661
  • Title

    Estimating Software Vulnerabilities: A Case Study Based on the Misclassification of Bugs in MySQL Server

  • Author

    Wright, Jason L. ; Larsen, Jason W. ; McQueen, Miles

  • Author_Institution
    Cyber Security R&D, Idaho Nat. Lab., Idaho Falls, ID, USA
  • fYear
    2013
  • fDate
    2-6 Sept. 2013
  • Firstpage
    72
  • Lastpage
    81
  • Abstract
    Software vulnerabilities are an important part of the modern software economy. Being able to accurately classify software defects as a vulnerability, or not, allows developers and end users to expend appropriately more effort on fixing those defects which have security implications. However, we demonstrate in this paper that the expected number of misclassified bugs (those not marked as also being vulnerabilities) may be quite high and thus human efforts to classify bug reports as vulnerabilities appears to be quite ineffective. We conducted an experiment using the MySQL bug report database to estimate the number of misclassified bugs yet to be identified as vulnerabilities. The MySQL database server versions we evaluated currently have 76 publicly reported vulnerabilities. Yet our experimental results show, with 95% confidence, that the MySQL bug database has between 499 and 587 misclassified bugs for the same software. This is an estimated increase of vulnerabilities between657% and 772% over the number currently identified and publicly reported in the National Vulnerability Database and the Open Source Vulnerability Database.
  • Keywords
    SQL; program debugging; relational databases; software reliability; MySQL bug report database; MySQL server; bug misclassification; national vulnerability database; open source vulnerability database; software vulnerability estimation; Computer bugs; Databases; Security; Servers; Sociology; Software; Statistics; bug reports; misclassification; software vulnerabilities; vulnerability estimation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2013 Eighth International Conference on
  • Conference_Location
    Regensburg
  • Type

    conf

  • DOI
    10.1109/ARES.2013.14
  • Filename
    6657228