Predicting Attack Prone Software Components using Repository Mined Change Metrics

Daniel Hein, Hossein Saiedian

2016

Abstract

Identification of attack-prone entities is a crucial step toward improving the state of information security in modern software based systems. Recent work in the fields of empirical software engineering and defect prediction show promise toward identifying and prioritizing attack prone entities using information extracted from software version control repositories. Equipped with knowledge of the most vulnerable entities, organizations can efficiently allocate resources to more effectively leverage secure software development practices, isolating and expunging vulnerabilities before they are released in production products. Such practices include security reviews, automated static analysis, and penetration testing, among others. Efficiently focusing secure development practices on entities of greatest need can help identify and eliminate vulnerabilities in a more cost effective manner when compared to wholesale application for large products.

Download


Paper Citation


in Harvard Style

Hein D. and Saiedian H. (2016). Predicting Attack Prone Software Components using Repository Mined Change Metrics . In Proceedings of the 2nd International Conference on Information Systems Security and Privacy - Volume 1: ICISSP, ISBN 978-989-758-167-0, pages 554-563. DOI: 10.5220/0005812905540563

in Bibtex Style

@conference{icissp16,
author={Daniel Hein and Hossein Saiedian},
title={Predicting Attack Prone Software Components using Repository Mined Change Metrics},
booktitle={Proceedings of the 2nd International Conference on Information Systems Security and Privacy - Volume 1: ICISSP,},
year={2016},
pages={554-563},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0005812905540563},
isbn={978-989-758-167-0},
}


in EndNote Style

TY - CONF
JO - Proceedings of the 2nd International Conference on Information Systems Security and Privacy - Volume 1: ICISSP,
TI - Predicting Attack Prone Software Components using Repository Mined Change Metrics
SN - 978-989-758-167-0
AU - Hein D.
AU - Saiedian H.
PY - 2016
SP - 554
EP - 563
DO - 10.5220/0005812905540563