Toward Non-security Failures as a Predictor of Security Faults and Failures

Toward Non-security Failures as a Predictor of Security Faults and Failures
复制标题

将非安全故障作为安全故障和失败的预测因素

DOI:
--
复制
发表时间:
2009
期刊:
Engineering Secure Software and Systems
影响因子:
--
通讯作者:
L. Williams
L. Williams
中科院分区:
--
文献类型:
--
作者:
M. Gegick;Pete Rotella;L. Williams

文献摘要

被引文献

相似文献

在寻找可以在软件生命周期早期预测漏洞存在的度量时,从非安全领域选择度量可能会有一些好处。我们分析了2007年思科软件系统报告的非安全性和安全性故障数据。我们使用非安全故障报告作为分类和回归树(CART)模型的输入变量,以确定组件至少存在一个漏洞的概率。使用CART,我们将所有系统组件按其概率降序排列,发现57%的脆弱组件位于总组件排名的前9%,但误报率为48%。结果表明,非安全故障可以作为安全相关预测模型的输入变量之一。
In the search for metrics that can predict the presence of vulnerabilities early in the software life cycle, there may be some benefit to choosing metrics from the non-security realm. We analyzed non-security and security failure data reported for the year 2007 of a Cisco software system. We used non-security failure reports as input variables into a classification and regression tree (CART) model to determine the probability that a component will have at least one vulnerability. Using CART, we ranked all of the system components in descending order of their probabilities and found that 57% of the vulnerable components were in the top nine percent of the total component ranking, but with a 48% false positive rate. The results indicate that non-security failures can be used as one of the input variables for security-related prediction models.