Experience Report: Study of Vulnerabilities of Enterprise Operating Systems

被引:14
作者
Gorbenko, Anatoliy [1 ]
Romanovsky, Alexander [2 ]
Tarasyuk, Olga [3 ]
Biloborodov, Oleksandr [4 ]
机构
[1] Leeds Beckett Univ, Sch Comp Creat Technol & Engn, Leeds, W Yorkshire, England
[2] Newcastle Univ, Sch Comp Sci, Newcastle Upon Tyne, Tyne & Wear, England
[3] Natl Aerosp Univ, Dept Comp Syst & Networks, Kharkov, Ukraine
[4] Plarium Ukraine LLC, Kharkov, Ukraine
来源
2017 IEEE 28TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING (ISSRE) | 2017年
基金
英国工程与自然科学研究理事会;
关键词
security; vulnerability; operating systems; vulnerability databases; days-of-risk; forever-day vulnerabilities; vulnerability life cycle; vulnerability statistics;
D O I
10.1109/ISSRE.2017.20
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This experience report analyses security problems of modern computer systems caused by vulnerabilities in their operating systems. An aggregated vulnerability database has been developed by joining vulnerability records from two publicly available vulnerability databases: the Common Vulnerabilities and Exposures system (CVE) and the National Vulnerabilities database (NVD). The aggregated data allow us to investigate the stages of the vulnerability life cycle, vulnerability disclosure and the elimination statistics for different operating systems. The specific technical areas the paper covers are the quantitative assessment of vulnerabilities discovered and fixed in operating systems, the estimation of time that vendors spend on patch issuing, and the analysis of the vulnerability criticality and identification of vulnerabilities common for different operating systems.
引用
收藏
页码:205 / 215
页数:11
相关论文
共 34 条
  • [11] Goodin D., 2012, RISE FOREVER DAY BUG
  • [12] Gorbenko Anatoliy, 2011, Software Engineering for Resilient Systems. Proceedings Third International Workshop (SERENE 2011), P145, DOI 10.1007/978-3-642-24124-6_14
  • [13] Hahn A, 2012, IEEE POW ENER SOC GE
  • [14] Jones J., 2007, BASIC GUIDE DAYS RIS
  • [15] Jones J., 2007, 2006 CLIENT OS DAYS
  • [16] Jones J., 2006, DAYS OF RISK 2006 LI
  • [17] Ladd B., 2017, The Race Between Security Professionals and Adversaries
  • [18] Littlewood B., 2004, LNCS, V3193
  • [19] Microsoft Inc, MICR SEC B
  • [20] Microsoft Inc, 2016, DESCR SOFTW UPD SERV