• DocumentCode
    2443296
  • Title

    Fast Abstract: Software Selection Based on Quantitative Security Risk Assessment

  • Author

    Das, Ruma ; Sarkani, Shahram ; Mazzuchi, Thomas A.

  • Author_Institution
    Eng. Manage. & Syst. Eng., George Washington Univ., Washington, DC, USA
  • fYear
    2012
  • fDate
    25-27 Oct. 2012
  • Firstpage
    171
  • Lastpage
    172
  • Abstract
    Multiple software products often exist on the same server and, thus, vulnerability in one product might compromise the entire environment. Therefore security risk assessments of the candidate software products, which are evaluated to be part of a larger system, are important. Having a quantitative security risk assessment model provides an objective criterion for such assessments as well as comparison between candidate software products. In this paper, we present our preliminary exploration of a software product evaluation method using such a quantitative security risk assessment model. Our goal is to utilize prior research in quantitative security risk assessment, which is based on empirical data from the National Vulnerability Database (NVD), and compare the security risk levels of the products evaluated. We are evaluating the application of topic modeling to build a security risk assessment model. Such a procedure could help decision makers evaluate and compare open-source software (OSS) products to ensure that they are safe and secure enough to be put into their environment.
  • Keywords
    public domain software; risk management; security of data; NVD; OSS; national vulnerability database; open-source software; quantitative security risk assessment; software products; software selection; Databases; Modeling; Open source software; Risk management; Security; Software systems; quantitative risk assessment; software evaluation; software security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    High-Assurance Systems Engineering (HASE), 2012 IEEE 14th International Symposium on
  • Conference_Location
    Omaha, NE
  • ISSN
    1530-2059
  • Print_ISBN
    978-1-4673-4742-6
  • Type

    conf

  • DOI
    10.1109/HASE.2012.10
  • Filename
    6376344