2021
DOI: 10.48550/arxiv.2107.08364
|View full text |Cite
Preprint
|
Sign up to set email alerts
|

A Survey on Data-driven Software Vulnerability Assessment and Prioritization

Abstract: Software Vulnerabilities (SVs) are increasing in complexity and scale, posing great security risks to many software systems. Given the limited resources in practice, SV assessment and prioritization help practitioners devise optimal SV mitigation plans based on various SV characteristics. The surge in SV data sources and datadriven techniques such as Machine Learning and Deep Learning have taken SV assessment and prioritization to the next level. Our survey provides a taxonomy of the past research efforts and … Show more

Help me understand this report
View published versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
9
0

Year Published

2021
2021
2021
2021

Publication Types

Select...
3

Relationship

3
0

Authors

Journals

citations
Cited by 3 publications
(9 citation statements)
references
References 124 publications
(265 reference statements)
0
9
0
Order By: Relevance
“…Bugzilla reports are usually assigned a severity score by the reporter of the SV. There are four classes of severity that may be assigned 5 : blocker, the bug significantly impacts users or causes data loss; critical/major, the bug severely impairs functionality and a satisfactory workaround does not exist; normal, the bug blocks non-critical functionality and a workaround exists; and minor, the bug has low or no impact to users.…”
Section: A Software Vulnerability Reporting Practicesmentioning
confidence: 99%
See 4 more Smart Citations
“…Bugzilla reports are usually assigned a severity score by the reporter of the SV. There are four classes of severity that may be assigned 5 : blocker, the bug significantly impacts users or causes data loss; critical/major, the bug severely impairs functionality and a satisfactory workaround does not exist; normal, the bug blocks non-critical functionality and a workaround exists; and minor, the bug has low or no impact to users.…”
Section: A Software Vulnerability Reporting Practicesmentioning
confidence: 99%
“…Other than impacts to SV prioritization, severity data inconsistency can also impact researchers who analyse severity data. One such task that has been regularly investigated is severity prediction [5]. selected stage for prediction, e.g., for bug reports [9] or SV databases [18].…”
Section: A Research Questionsmentioning
confidence: 99%
See 3 more Smart Citations