Cluster-based vulnerability assessment of operating systems and web browsers

被引:0
|
作者
Yazdan Movahedi
Michel Cukier
Ambrose Andongabo
Ilir Gashi
机构
[1] University of Maryland,
[2] City,undefined
[3] University of London,undefined
来源
Computing | 2019年 / 101卷
关键词
Vulnerability assessment; Nonhomogeneous Poisson process; Clustering; Software reliability models; Software reliability growth; Security growth models; 62H30; 68M15;
D O I
暂无
中图分类号
学科分类号
摘要
Organizations face the issue of how to best allocate their security resources. Thus, they need an accurate method for assessing how many new vulnerabilities will be reported for the operating systems (OSs) and web browsers they use in a given time period. Our approach consists of clustering vulnerabilities by leveraging the text information within vulnerability records, and then simulating the mean value function of vulnerabilities by relaxing the monotonic intensity function assumption, which is prevalent among the studies that use software reliability models (SRMs) and nonhomogeneous Poisson process in modeling. We applied our approach to the vulnerabilities of four OSs (Windows, Mac, IOS, and Linux) and four web browsers (Internet Explorer, Safari, Firefox, and Chrome). Out of the total eight OSs and web browsers we analyzed using a power-law model issued from a family of SRMs, the model was statistically adequate for modeling in six cases. For these cases, in terms of estimation and forecasting capability, our results, compared to a power-law model without clustering, are more accurate in all cases but one.
引用
收藏
页码:139 / 160
页数:21
相关论文
共 50 条
  • [22] Adaptive Request Distribution in Cluster-Based Web System
    Zatwarnicki, Krzysztof
    KNOWLEDGE-BASED AND INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS, PT I: 15TH INTERNATIONAL CONFERENCE, KES 2011, 2011, 6881 : 42 - 51
  • [23] The Cluster-Based Time-Aware Web System
    Zatwarnicki, Krzysztof
    Zatwarnicka, Anna
    COMPUTER NETWORKS, CN 2014, 2014, 431 : 37 - 46
  • [24] A cluster-based web service discovery in MANET environments
    Kim, Yeon-Seok
    Shim, Yoo-Seok
    Lee, Kyong-Ho
    MOBILE INFORMATION SYSTEMS, 2011, 7 (04) : 299 - 315
  • [25] Automated cluster-based web service performance tuning
    Chung, IH
    Hollingsworth, JK
    13TH IEEE INTERNATIONAL SYMPOSIUM ON HIGH PERFORMANCE DISTRIBUTED COMPUTING, PROCEEDINGS, 2004, : 36 - 44
  • [26] The Cluster-Based Time-Aware Web System
    1600, Springer Verlag (431):
  • [27] Improving application placement for cluster-based web applications
    Tian C.
    Jiang H.
    Iyengar A.
    Liu X.
    Wu Z.
    Chen J.
    Liu W.
    Wang C.
    IEEE Transactions on Network and Service Management, 2011, 8 (02): : 104 - 115
  • [28] A completely distributed architecture for cluster-based web servers
    Du, ZK
    Ju, JB
    PARALLEL AND DISTRIBUTED COMPUTING, APPLICATIONS AND TECHNOLOGIES, PDCAT'2003, PROCEEDINGS, 2003, : 483 - 487
  • [29] A cluster-based approach for the innovation assessment of countries
    Onsel, Sule
    Ulengin, Fusun
    Kabak, Ozgur
    IEMC - EUROPE 2008: INTERNATIONAL ENGINEERING MANAGEMENT CONFERENCE, EUROPE, CONFERENCE PROCEEDINGS: MANAGING ENGINEERING, TECHNOLOGY AND INNOVATION FOR GROWTH, 2008, : 293 - 297
  • [30] Cluster-based approaches to extended systems.
    Gordon, MS
    ABSTRACTS OF PAPERS OF THE AMERICAN CHEMICAL SOCIETY, 2004, 228 : U219 - U219