基于组件依赖图的软件安全漏洞预测方法

Sheng Jun Wei, Tao He*, Chang Zhen Hu, Chun Shan

*此作品的通讯作者

科研成果: 期刊稿件文章同行评审

4 引用 (Scopus)

摘要

Aiming at the prediction of vulnerability, a vulnerability prediction method based on the component dependency graph was proposed. Firstly, the complexity, coupling and cohesion metrics of a software component were defined based on the component dependency graph. Then these metrics were used to establish a machine learning model to predict vulnerabilities in a component. Finally, a crawler tool was designed and implemented to collect all public security vulnerabilities in Mozilla Firefox from version 1.0 to version 43. Based on these data, the prediction model was trained and tested. The results show that the proposed metrics are also effective in vulnerability prediction.

投稿的翻译标题Predicting Software Security Vulnerabilities withComponent Dependency Graphs
源语言繁体中文
页(从-至)525-530
页数6
期刊Beijing Ligong Daxue Xuebao/Transaction of Beijing Institute of Technology
38
5
DOI
出版状态已出版 - 1 5月 2018

关键词

  • Component dependency graph
  • Machine learning
  • Software security
  • Vulnerability prediction

指纹

探究 '基于组件依赖图的软件安全漏洞预测方法' 的科研主题。它们共同构成独一无二的指纹。

引用此