Annual Reliability and Maintainability Symposium, 2005. Proceedings.
DOI: 10.1109/rams.2005.1408432
|View full text |Cite
|
Sign up to set email alerts
|

Quantitative vulnerability assessment of systems software

Abstract: Operating systems represent complex interactive software systems that control access to information. Vulnerabilities present in such software represent significant security risks. In this paper, we examine the feasibility of quantitatively characterization of vulnerabilities. For Windows 98 and Windows NT 4.0, we present plots for cumulative numbers of vulnerabilities found. A time-based model for the total vulnerabilities discovered is proposed and is fitted to the data for two operating systems. We introduce… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
87
0

Publication Types

Select...
3
2

Relationship

0
5

Authors

Journals

citations
Cited by 76 publications
(87 citation statements)
references
References 8 publications
0
87
0
Order By: Relevance
“…The technical support for that version and hence the frequency of update patches will then begin to decline. This s-shaped behavior shown in Figure 4 can be described by a time-based model introduced earlier by Alhazmi and Malaiya [16]. Let y be the cumulative number of vulnerabilities.…”
Section: Modeling the Vulnerability Discovery Processmentioning
confidence: 96%
See 4 more Smart Citations
“…The technical support for that version and hence the frequency of update patches will then begin to decline. This s-shaped behavior shown in Figure 4 can be described by a time-based model introduced earlier by Alhazmi and Malaiya [16]. Let y be the cumulative number of vulnerabilities.…”
Section: Modeling the Vulnerability Discovery Processmentioning
confidence: 96%
“…The similarity of the plots in the later phase suggests that Windows 98 and Windows 95 shared a significant fraction of the code. The installed base of Windows 98 peaked during 1999-2000 [16]. At some time after this, the discovery rates of vulnerabilities in both versions slowed down.…”
Section: An Examination Of the Remaining Vulnerabilitiesmentioning
confidence: 99%
See 3 more Smart Citations