Title :
Fast Abstract: Software Selection Based on Quantitative Security Risk Assessment
Author :
Das, Ruma ; Sarkani, Shahram ; Mazzuchi, Thomas A.
Author_Institution :
Eng. Manage. & Syst. Eng., George Washington Univ., Washington, DC, USA
Abstract :
Multiple software products often exist on the same server and, thus, vulnerability in one product might compromise the entire environment. Therefore security risk assessments of the candidate software products, which are evaluated to be part of a larger system, are important. Having a quantitative security risk assessment model provides an objective criterion for such assessments as well as comparison between candidate software products. In this paper, we present our preliminary exploration of a software product evaluation method using such a quantitative security risk assessment model. Our goal is to utilize prior research in quantitative security risk assessment, which is based on empirical data from the National Vulnerability Database (NVD), and compare the security risk levels of the products evaluated. We are evaluating the application of topic modeling to build a security risk assessment model. Such a procedure could help decision makers evaluate and compare open-source software (OSS) products to ensure that they are safe and secure enough to be put into their environment.
Keywords :
public domain software; risk management; security of data; NVD; OSS; national vulnerability database; open-source software; quantitative security risk assessment; software products; software selection; Databases; Modeling; Open source software; Risk management; Security; Software systems; quantitative risk assessment; software evaluation; software security;
Conference_Titel :
High-Assurance Systems Engineering (HASE), 2012 IEEE 14th International Symposium on
Conference_Location :
Omaha, NE
Print_ISBN :
978-1-4673-4742-6
DOI :
10.1109/HASE.2012.10