DocumentCode :
3106647
Title :
A comparative study of vulnerability discovery modeling and software reliability growth modeling
Author :
Kapur, P.K. ; Yadavali, V.S.S. ; Shrivastava, A.K.
Author_Institution :
Center for Interdiscipl. Res., Amity Univ., Noida, India
fYear :
2015
fDate :
25-27 Feb. 2015
Firstpage :
246
Lastpage :
251
Abstract :
Technological advancements are achieving greater heights with each passing day. Information technology is one of the area in which is developing at an agile pace. It has evolved in such a way that we all are interconnected through some medium viz. Internet, telecommunication etc. Technical advancements have grown enough to affect everyone´s day to day life. With this increasing dependency on software systems the issue of being secure is a big challenge. This security problem is becoming critical due to the presence of bad guys and attracted a lot of researchers towards identifying major attributes of security. One of the security attribute considered in this paper is software vulnerability. Software security vulnerability is a weakness in a software product that could allow an attacker to compromise the integrity, availability, or confidentiality of that product. In past, Vulnerabilities have been reported in the various operating systems. In order to mitigate the risk associated with these vulnerabilities both the developers as well as the users have to utilize their significant resources. Recently few researchers have shown their interest in investigating the potential number of vulnerabilities in the software by applying quantitative approach. In this paper we analytically describe existing models and compare it with our proposed models by evaluating these models using actual data for various software systems. Our proposed models capture the discovery process relatively better than the existing discovery models. Further it has also been shown that some of the existing SRGM can also be used for predicting security vulnerabilities in software.
Keywords :
program verification; risk management; security of data; software reliability; Internet; SRGM; information technology; model evaluation; product availability; product confidentiality; product integrity; quantitative approach; risk mitigatation; security attributes; security problem; software product; software reliability growth modeling; software security vulnerability prediction; software system dependency; technical advancement; technological advancement; telecommunication; vulnerability discovery modeling; Analytical models; Computational modeling; Mathematical model; Security; Software reliability; Software systems; Non Homogeneous Poisson Process (NHPP); Software Reliability Growth Model (SRGM); Software Security; Vulnerability; Vulnerability Discovery Model (VDM);
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Futuristic Trends on Computational Analysis and Knowledge Management (ABLAZE), 2015 International Conference on
Conference_Location :
Noida
Print_ISBN :
978-1-4799-8432-9
Type :
conf
DOI :
10.1109/ABLAZE.2015.7155000
Filename :
7155000
Link To Document :
بازگشت