Security of open source web applications

Security of open source web applications
复制标题

开源 Web 应用程序的安全性

DOI:
10.1109/esem.2009.5314215
复制
发表时间:
2009
期刊:
2009 3rd International Symposium on Empirical Software Engineering and Measurement
影响因子:
--
通讯作者:
Michael Whelan
Michael Whelan
中科院分区:
--
文献类型:
--
作者:
J. Walden;M. Doyle;Grant A. Welch;Michael Whelan

文献摘要

被引文献

相似文献

在对14个广泛使用的开源PHP Web应用程序的实证研究中,我们发现,从2006年夏季到2008年夏季,聚合代码库的漏洞密度从8.88个漏洞/Kbps下降到3.30个。单个Web应用程序差异很大,在研究开始时,漏洞密度从0到121.4不等。虽然安全问题的总数减少了,但在分析期间,14个应用程序中有8个的漏洞密度增加了。我们开发了一个安全资源指标度量,我们发现它与漏洞密度随时间的变化具有很强的相关性(ρ = 0.67,p < 0.05)。传统的软件度量,如代码大小、圈复杂度、嵌套复杂度和流失,与漏洞密度有显著的相关性(p < 0.05),但相关性要小得多(最多ρ = 0.31)。使用Fortify Source Code Analyzer静态分析工具测量漏洞密度。
In an empirical study of fourteen widely used open source PHP web applications, we found that the vulnerability density of the aggregate code base decreased from 8.88 vulnerabilities/KLOC to 3.30 from Summer 2006 to Summer 2008. Individual web applications varied widely, with vulnerability densities ranging from 0 to 121.4 at the beginning of the study. While the total number of security problems decreased, vulnerability density increased in eight of the fourteen applications over the analysis period. We developed a security resources indicator metric, which we found to be strongly correlated (ρ =0.67,p < 0.05) with change in vulnerability density over time. Traditional software metrics, such as code size, cyclomatic complexity, nesting complexity, and churn, had significant (p < 0.05) but much smaller correlations (ρ = 0.31 at best) with vulnerability density. Vulnerability density was measured using the Fortify Source Code Analyzer static analysis tool.