Cluster-based vulnerability assessment of operating systems and web browsers

被引:0
|
作者
Yazdan Movahedi
Michel Cukier
Ambrose Andongabo
Ilir Gashi
机构
[1] University of Maryland,
[2] City,undefined
[3] University of London,undefined
来源
Computing | 2019年 / 101卷
关键词
Vulnerability assessment; Nonhomogeneous Poisson process; Clustering; Software reliability models; Software reliability growth; Security growth models; 62H30; 68M15;
D O I
暂无
中图分类号
学科分类号
摘要
Organizations face the issue of how to best allocate their security resources. Thus, they need an accurate method for assessing how many new vulnerabilities will be reported for the operating systems (OSs) and web browsers they use in a given time period. Our approach consists of clustering vulnerabilities by leveraging the text information within vulnerability records, and then simulating the mean value function of vulnerabilities by relaxing the monotonic intensity function assumption, which is prevalent among the studies that use software reliability models (SRMs) and nonhomogeneous Poisson process in modeling. We applied our approach to the vulnerabilities of four OSs (Windows, Mac, IOS, and Linux) and four web browsers (Internet Explorer, Safari, Firefox, and Chrome). Out of the total eight OSs and web browsers we analyzed using a power-law model issued from a family of SRMs, the model was statistically adequate for modeling in six cases. For these cases, in terms of estimation and forecasting capability, our results, compared to a power-law model without clustering, are more accurate in all cases but one.
引用
收藏
页码:139 / 160
页数:21
相关论文
共 50 条
  • [1] Cluster-based vulnerability assessment of operating systems and web browsers
    Movahedi, Yazdan
    Cukier, Michel
    Andongabo, Ambrose
    Gashi, Ilir
    COMPUTING, 2019, 101 (02) : 139 - 160
  • [2] Cluster-based Vulnerability Assessment Applied to Operating Systems
    Movahedi, Yazdan
    Cukier, Michel
    Andongabo, Ambrose
    Gashi, Ilir
    2017 13TH EUROPEAN DEPENDABLE COMPUTING CONFERENCE (EDCC 2017), 2017, : 18 - 25
  • [3] Guaranteeing the quality of service in cluster-based Web systems
    Zatwarnicki, Krzysztof
    Borzemski, Leszek
    ADVANCES IN KNOWLEDGE-BASED AND INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS, 2012, 243 : 1141 - 1150
  • [4] Operating systems support for programmable cluster-based Internet routers
    Pradhan, Prashant
    Chiueh, Tzi-Cker
    Proceedings of the Workshop on Hot Topics in Operating Systems - HOTOS, 1999, : 76 - 81
  • [5] Cluster-Based Web Service Recommendation
    Kumara, Banage T. G. S.
    Paik, Incheon
    Siriweera, T. H. A. S.
    Koswatte, Koswatte R. C.
    PROCEEDINGS 2016 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING (SCC 2016), 2016, : 348 - 355
  • [6] Adaptive Prefetching Scheme Using Web Log Mining in Cluster-based Web Systems
    Lee, Heung Ki
    An, Baik Song
    Kim, Eun Jung
    2009 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, VOLS 1 AND 2, 2009, : 903 - 910
  • [7] AN APPROACH FOR DETECTING SECURITY VULNERABILITIES IN WEB BROWSERS FOR MOBILE OPERATING SYSTEMS
    Mechev, Stoyan
    MATHEMATICS AND INFORMATICS, 2024, 67 (05): : 475 - 488
  • [8] A Fuzzy Adaptive Request Distribution algorithm for cluster-based Web systems
    Borzemski, L
    Zatwarnicki, K
    ELEVENTH EUROMICRO CONFERENCE ON PARALLEL, DISTRIBUTED AND NETWORK-BASED PROCESSING, PROCEEDINGS, 2003, : 119 - 126
  • [9] Cluster-based Data Sharing for Web 3.0 in Intelligent Transportation Systems
    Alkhathami, Mohammed
    JOURNAL OF WEB ENGINEERING, 2024, 23 (07): : 1025 - 1040
  • [10] Application of Neural Networks in Distribution of the Load in Cluster-Based Web Systems
    Pokuta, Waldemar
    Zatwarnicki, Krzysztof
    APPLIED SCIENCES-BASEL, 2022, 12 (01):