TY - GEN
T1 - Improving vulnerability prediction accuracy with Secure Coding Standard violation measures
AU - Yang, Joonseok
AU - Ryu, Duksan
AU - Baik, Jongmoon
N1 - Publisher Copyright:
© 2016 IEEE.
PY - 2016
Y1 - 2016
N2 - As the need of software has been increasing, the danger of malicious attacks against software has been worse. In order to fortify software systems against adversaries, researchers have devoted significant efforts on mitigating software vulnerabilities. To eliminate security vulnerabilities from software with lower inspection effort, vulnerability prediction approaches have been emerged. By allocating human and time resource on the potentially vulnerable subset, development organization could eliminate vulnerabilities in a cost effective manner. In the vulnerability prediction approaches, a vulnerability prediction model is constructed based on various software attributes. However, vulnerability prediction models based on the traditional software attributes have provided poor prediction accuracy or low cost effectiveness since the traditional software attributes are unable to reflect vulnerability characteristics sufficiently. In this paper, we propose a novel vulnerability prediction approach based on the CERT-C Secure Coding Standard. To evaluate the efficacy of the proposed approach, the prediction results of the suggested prediction models and other traditional models were assessed in terms of prediction accuracy and cost effectiveness. The results show that the proposed method can improve the vulnerability prediction accuracy.
AB - As the need of software has been increasing, the danger of malicious attacks against software has been worse. In order to fortify software systems against adversaries, researchers have devoted significant efforts on mitigating software vulnerabilities. To eliminate security vulnerabilities from software with lower inspection effort, vulnerability prediction approaches have been emerged. By allocating human and time resource on the potentially vulnerable subset, development organization could eliminate vulnerabilities in a cost effective manner. In the vulnerability prediction approaches, a vulnerability prediction model is constructed based on various software attributes. However, vulnerability prediction models based on the traditional software attributes have provided poor prediction accuracy or low cost effectiveness since the traditional software attributes are unable to reflect vulnerability characteristics sufficiently. In this paper, we propose a novel vulnerability prediction approach based on the CERT-C Secure Coding Standard. To evaluate the efficacy of the proposed approach, the prediction results of the suggested prediction models and other traditional models were assessed in terms of prediction accuracy and cost effectiveness. The results show that the proposed method can improve the vulnerability prediction accuracy.
KW - CERT-C Secure Coding Standard
KW - Security
KW - Software Engineering
KW - Vulnerability
KW - Vulnerability Prediction
UR - https://www.scopus.com/pages/publications/84964669821
U2 - 10.1109/BIGCOMP.2016.7425809
DO - 10.1109/BIGCOMP.2016.7425809
M3 - Conference paper
AN - SCOPUS:84964669821
T3 - 2016 International Conference on Big Data and Smart Computing, BigComp 2016
SP - 115
EP - 122
BT - 2016 International Conference on Big Data and Smart Computing, BigComp 2016
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - International Conference on Big Data and Smart Computing, BigComp 2016
Y2 - 18 January 2016 through 20 January 2016
ER -