Quantitative vulnerability assessment of systems software

114Citations
Citations of this article
67Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Operating systems represent complex interactive software systems that control access to information. Vulnerabilities present in such software represent significant security risks. In this paper, we examine the feasibility of quantitatively characterization of vulnerabilities. For Windows 98 and Windows NT 4.0, we present plots for cumulative numbers of vulnerabilities found. A time-based model for the total vulnerabilities discovered is proposed and is fitted to the data for two operating systems. We introduce a measure termed equivalent effort and propose an alternative model which is analogous to the software reliability growth models. We have shown that both models fit well and the fit is significant. We discuss the feasibility of using a new measure termed vulnerability density. We present the data on known defect densities for the two operating systems and discuss the relation between densities of vulnerabilities and the general defects. This relationship could lead us to potential ways of estimating the number of vulnerabilities in future. © 2005 IEEE.

Cite

CITATION STYLE

APA

Alhazmi, O. H., & Malaiya, Y. K. (2005). Quantitative vulnerability assessment of systems software. In Proceedings - Annual Reliability and Maintainability Symposium (pp. 615–620). https://doi.org/10.1109/rams.2005.1408432

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free