Toward Non-security Failures as a Predictor of Security Faults and Failures
Toward Non-security Failures as a Predictor of Security Faults and Failures
复制标题
将非安全故障作为安全故障和失败的预测因素
DOI:
--
复制
发表时间:
2009
期刊:
影响因子:
--
通讯作者:
L. Williams
中科院分区:
文献类型:
--
作者:
M. Gegick;Pete Rotella;L. Williams
In the search for metrics that can predict the presence of vulnerabilities early in the software life cycle, there may be some benefit to choosing metrics from the non-security realm. We analyzed non-security and security failure data reported for the year 2007 of a Cisco software system. We used non-security failure reports as input variables into a classification and regression tree (CART) model to determine the probability that a component will have at least one vulnerability. Using CART, we ranked all of the system components in descending order of their probabilities and found that 57% of the vulnerable components were in the top nine percent of the total component ranking, but with a 48% false positive rate. The results indicate that non-security failures can be used as one of the input variables for security-related prediction models.