Abstract
Ozment and Schechter (USENIX Security'2006) analyzed the evolution of OpenBSD vulnerabilities over the span of 7 years (1998-2005) and concluded that its security increases with age. In this paper, we extend their study by analyzing the evolution of OpenBSD vulnerabilities over the span of 22 years (1998-2020) and Firefox vulnerabilities over the span of 9 years (2011-2020). Our empirical study leads to a number of insights, including the following: both OpenBSD and Firefox get more secure (i.e., less vulnerable) with time, but today's developers do not necessarily produce more secure code; OpenBSD and Firefox developers tend to make similar security mistakes, but Firefox vulnerabilities are easier to exploit; finally, Firefox's vulnerability density is almost one order of magnitude higher than OpenBSD's, meaning Firefox is more vulnerable.
Author supplied keywords
Cite
CITATION STYLE
Shi, J., Zou, D., Xu, S., Deng, X., & Jin, H. (2023). Does OpenBSD and Firefox’s Security Improve with Time? IEEE Transactions on Dependable and Secure Computing, 20(4), 2781–2793. https://doi.org/10.1109/TDSC.2022.3153325
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.