E-WBM: An Effort-Based Vulnerability Discovery Model

Xiajing Wang, Rui Ma*, Binbin Li, Donghai Tian, Xuefei Wang

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

11 Citations (Scopus)

Abstract

Vulnerability discovery models (VDMs) have recently been proposed to estimate the cumulative number of vulnerabilities that will be disclosed after software is released. A precise VDM would offer an available quantitative insight to assess software security. Even though VDM has demonstrated its effectiveness in multiple software, it remains limited in accuracy, especially with weak versatility. We propose a novel effort-based VDMs, named E-WBM, to improve critical vulnerability discovery rate algorithm using Weibull probability distribution function towards efficient vulnerability discovery models. E-WBM accurately portrays the trend of software security vulnerabilities disclosure. We evaluate E-WBM on eight popular real-world operating systems and show the feasibility of the proposed model. We further compare E-WBM with a state-of-the-art effort-based model AME and time-based model JW on the above eight operating systems. Our comparison also demonstrates that E-WBM consistently outperforms AME and JW both at reducing the deviations and fitting curve trends. In addition to the model fitting, predictive capabilities of two effort-based models E-WBM and AME are also examined. The results show that the E-WBM model yields a more stable prediction with a significantly less error than AME.

Original languageEnglish
Article number8676014
Pages (from-to)44276-44292
Number of pages17
JournalIEEE Access
Volume7
DOIs
Publication statusPublished - 2019

Keywords

  • AME
  • E-WBM
  • JW
  • Vulnerability discovery model
  • testing effort

Fingerprint

Dive into the research topics of 'E-WBM: An Effort-Based Vulnerability Discovery Model'. Together they form a unique fingerprint.

Cite this