Security of open source web applications
Security of open source web applications
复制标题
开源 Web 应用程序的安全性
DOI:
10.1109/esem.2009.5314215
复制
发表时间:
2009
期刊:
影响因子:
--
通讯作者:
Michael Whelan
中科院分区:
文献类型:
--
作者:
J. Walden;M. Doyle;Grant A. Welch;Michael Whelan
In an empirical study of fourteen widely used open source PHP web applications, we found that the vulnerability density of the aggregate code base decreased from 8.88 vulnerabilities/KLOC to 3.30 from Summer 2006 to Summer 2008. Individual web applications varied widely, with vulnerability densities ranging from 0 to 121.4 at the beginning of the study. While the total number of security problems decreased, vulnerability density increased in eight of the fourteen applications over the analysis period. We developed a security resources indicator metric, which we found to be strongly correlated (ρ =0.67,p < 0.05) with change in vulnerability density over time. Traditional software metrics, such as code size, cyclomatic complexity, nesting complexity, and churn, had significant (p < 0.05) but much smaller correlations (ρ = 0.31 at best) with vulnerability density. Vulnerability density was measured using the Fortify Source Code Analyzer static analysis tool.