Can we use software bug reports to identify vulnerability discovery strategies

计算机科学 脆弱性(计算) 软件错误 软件 漏洞管理 软件工程 软件开发 脆弱性评估
作者
Farzana Ahamed Bhuiyan,Raunak Shakya,Akond Rahman
标识
DOI:10.1145/3384217.3385618
摘要

Daily horror stories related to software vulnerabilities necessitates the understanding of how vulnerabilities are discovered. Identification of data sources that can be leveraged to understand how vulnerabilities are discovered could aid cybersecurity researchers to characterize exploitation of vulnerabilities. The goal of the paper is to help cybersecurity researchers in characterizing vulnerabilities by conducting an empirical study of software bug reports. We apply qualitative analysis on 729, 908, and 5336 open source software (OSS) bug reports respectively, collected from Gentoo, LibreOffice, and Mozilla to investigate if bug reports include vulnerability discovery strategies i.e. sequences of computation and/or cognitive activities that an attacker performs to discover vulnerabilities, where the vulnerability is indexed by a credible source, such as the National Vulnerability Database (NVD). We evaluate two approaches namely, text feature-based approach and regular expression-based approach to automatically identify bug reports that include vulnerability discovery strategies. We observe the Gentoo, LibreOffice, and Mozilla bug reports to include vulnerability discovery strategies. Using text feature-based prediction models, we observe the highest prediction performance for the Mozilla dataset with a recall of 0.78. Using the regular expression-based approach we observe recall to be 0.83 for the same dataset. Findings from our paper provide the groundwork for cybersecurity researchers to use OSS bug reports as a data source for advancing the science of vulnerabilities.

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
热情河马发布了新的文献求助10
刚刚
Hus11221发布了新的文献求助10
3秒前
4秒前
鸭鸭完成签到,获得积分10
4秒前
缥缈夏彤完成签到,获得积分10
5秒前
宗师算个瓢啊完成签到 ,获得积分10
6秒前
醒略略发布了新的文献求助10
7秒前
8秒前
9秒前
9秒前
彭于晏应助鱼先生采纳,获得30
10秒前
阿旭完成签到,获得积分10
11秒前
11秒前
squirrelcone发布了新的文献求助10
11秒前
阿旭发布了新的文献求助10
14秒前
水清梦蓝完成签到 ,获得积分10
14秒前
wujiasheng发布了新的文献求助10
15秒前
sunnnn发布了新的文献求助20
18秒前
SciGPT应助醒略略采纳,获得20
19秒前
慕容冷之关注了科研通微信公众号
19秒前
李爱国应助123采纳,获得10
20秒前
lily关注了科研通微信公众号
22秒前
Laura完成签到,获得积分10
27秒前
28秒前
小蘑菇应助aaa采纳,获得20
32秒前
32秒前
Hello应助月明星稀采纳,获得10
33秒前
酷波er应助Echodeng采纳,获得10
33秒前
33秒前
34秒前
orixero应助开放怀亦采纳,获得10
34秒前
lily发布了新的文献求助10
34秒前
SOLOMON应助winter采纳,获得10
35秒前
秋雪瑶应助跳跳骑士采纳,获得10
35秒前
37秒前
Phoenix完成签到,获得积分10
39秒前
40秒前
华仔应助洛芷采纳,获得10
41秒前
稚气满满完成签到 ,获得积分10
41秒前
大锤发布了新的文献求助10
42秒前
高分求助中
请在求助之前详细阅读求助说明!!!! 20000
The Three Stars Each: The Astrolabes and Related Texts 900
Multifunctional Agriculture, A New Paradigm for European Agriculture and Rural Development 600
Bernd Ziesemer - Maos deutscher Topagent: Wie China die Bundesrepublik eroberte 500
A radiographic standard of reference for the growing knee 400
Glossary of Geology 400
Additive Manufacturing Design and Applications 320
热门求助领域 (近24小时)
化学 材料科学 医学 生物 有机化学 工程类 生物化学 纳米技术 物理 内科学 计算机科学 化学工程 复合材料 遗传学 基因 物理化学 催化作用 电极 光电子学 量子力学
热门帖子
关注 科研通微信公众号,转发送积分 2476017
求助须知:如何正确求助?哪些是违规求助? 2140431
关于积分的说明 5454905
捐赠科研通 1863737
什么是DOI,文献DOI怎么找? 926542
版权声明 562846
科研通“疑难数据库(出版商)”最低求助积分说明 495727