• DocumentCode
    2803440
  • Title

    Measuring and Enhancing Prediction Capabilities of Vulnerability Discovery Models for Apache and IIS HTTP Servers

  • Author

    Alhazmi, Omar H. ; Malaiya, Yashwant K.

  • Author_Institution
    Colorado State Univ., Boulder, CO
  • fYear
    2006
  • fDate
    7-10 Nov. 2006
  • Firstpage
    343
  • Lastpage
    352
  • Abstract
    The prediction of the number of vulnerabilities in an HTTP server can allow us to evaluate the security risk associated with its use. Vulnerability discovery models have recently been proposed which can be used to estimate the future number of vulnerabilities expected to be discovered. A detailed analysis of the prediction capabilities of two models termed AML and LVD for the vulnerabilities in the two major HTTP servers is presented. Four complete data sets for Apache and US are used, representing an open source and a commercial Web server respectively. Both long term predictions involving several years and short term predictions for the following year are considered. Potential methods for enhancing the prediction accuracy are considered. The results show good predictive capabilities of the AML model when constraints are used for estimating the model parameters. The LVD model works well in some special cases when saturation has not yet set in. The results can be used by both developers to plan the test and maintenance effort needed and by users to assess the potential security risks associated with a specific server
  • Keywords
    Internet; file servers; risk analysis; security of data; AML model; Apache server; HTTP server; Internet Information Service; LVD model; Web server; security risk; vulnerability discovery models; Accuracy; Data security; HTML; Internet; Operating systems; Parameter estimation; Predictive models; Protocols; System testing; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Reliability Engineering, 2006. ISSRE '06. 17th International Symposium on
  • Conference_Location
    Raleigh, NC
  • ISSN
    1071-9458
  • Print_ISBN
    0-7695-2684-5
  • Type

    conf

  • DOI
    10.1109/ISSRE.2006.26
  • Filename
    4022000