Modeling Skewness in Vulnerability Discovery

被引:18
|
作者
Joh, HyunChul [1 ]
Malaiya, Yashwant K. [2 ]
机构
[1] Gwangju Inst Sci & Technol, Sch Gen Studies, Kwangju 500712, South Korea
[2] Colorado State Univ, Comp Sci Dept, Ft Collins, CO 80523 USA
关键词
data models; security; empirical studies; vulnerability discovery model (VDM); skewness;
D O I
10.1002/qre.1567
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
A vulnerability discovery model attempts to model the rate at which the vulnerabilities are discovered in a software product. Recent studies have shown that the S-shaped Alhazmi-Malaiya Logistic (AML) vulnerability discovery model often fits better than other models and demonstrates superior prediction capabilities for several major software systems. However, the AML model is based on the logistic distribution, which assumes a symmetrical discovery process with a peak in the center. Hence, it can be expected that when the discovery process does not follow a symmetrical pattern, an asymmetrical distribution based discovery model might perform better. Here, the relationship between performance of S-shaped vulnerability discovery models and the skewness in target vulnerability datasets is examined. To study the possible dependence on the skew, alternative S-shaped models based on the Weibull, Beta, Gamma and Normal distributions are introduced and evaluated. The models are fitted to data from eight major software systems. The applicability of the models is examined using two separate approaches: goodness of fit test to see how well the models track the data, and prediction capability using average error and average bias measures. It is observed that an excellent goodness of fit does not necessarily result in a superior prediction capability. The results show that when the prediction capability is considered, all the right skewed datasets are represented better with the Gamma distribution-based model. The symmetrical models tend to predict better for left skewed datasets; the AML model is found to be the best among them. Copyright (c) 2013 John Wiley & Sons, Ltd.
引用
收藏
页码:1445 / 1459
页数:15
相关论文
共 50 条
  • [41] An Intelligent and Automated WCMS Vulnerability-Discovery Tool: The Current State of the Web
    Cigoj, Primoz
    Blazic, Borka Jerman
    IEEE ACCESS, 2019, 7 : 175466 - 175473
  • [42] Framework for Web Application Vulnerability Discovery and Mitigation by Customizing Rules through ModSecurity
    Jain, Trapti
    Jain, Nakul
    2019 6TH INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND INTEGRATED NETWORKS (SPIN), 2019, : 643 - 648
  • [43] A new estimate of skewness with mean-squared error smaller than that of the sample skewness
    Shore, H
    COMMUNICATIONS IN STATISTICS-SIMULATION AND COMPUTATION, 1996, 25 (02) : 403 - 414
  • [44] Skewness of Travel Time Distribution
    Kim, Joo-Cheol
    Jung, Kwansue
    PROCEEDINGS OF THE 35TH IAHR WORLD CONGRESS, VOLS I AND II, 2013, : 2637 - 2645
  • [45] The skewness of commodity futures returns
    Fernandez-Perez, Adrian
    Frijns, Bart
    Fuertes, Ana-Maria
    Miffre, Joelle
    JOURNAL OF BANKING & FINANCE, 2018, 86 : 143 - 158
  • [46] Skewness and the crossing numbers of graphs
    Ding, Zongpeng
    AIMS MATHEMATICS, 2023, 8 (10): : 23989 - 23996
  • [47] On the Skewness of the LMS Adaptive Weights
    Silva, Thiago T. P.
    Igreja, Filipe
    Lara, Pedro
    Tarrataca, Luis
    Kar, Asutosh
    Haddad, Diego B.
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS II-EXPRESS BRIEFS, 2021, 68 (08) : 3022 - 3026
  • [48] Comparative Optimism and Event Skewness
    Rose, Jason P.
    Aspiras, Olivia
    Vogel, Erin
    Haught, Heather
    Roberts, Lindsay
    JOURNAL OF BEHAVIORAL DECISION MAKING, 2017, 30 (02) : 236 - 255
  • [49] Simultaneous Estimation of Skewness Parameters
    Ahmed, Syed Ejaz
    Nartey, Elfreda Narkuwor
    EIGHTEENTH INTERNATIONAL CONFERENCE ON MANAGEMENT SCIENCE AND ENGINEERING MANAGEMENT, ICMSEM 2024, 2024, 215 : 657 - 669
  • [50] Are preferences for skewness fixed or fungible?
    Gunnarsson, S
    Shogren, JF
    Cherry, TL
    ECONOMICS LETTERS, 2003, 80 (01) : 113 - 121