Javascript must be enabled to continue!
Empirical Validation of Software Metrics for Software Security Vulnerability Prediction
View through CrossRef
The increasing vulnerability of software systems and the potential for significant damages caused by security flaws necessitate the prediction of vulnerable components before deployment. Existing Vulnerability Prediction Models (VPMs) have not achieved an acceptable threshold for cross-project prediction performance, often sacrificing traceability for accuracy. Static analyzers suffer from false positives and false negatives. This study aims to create a software vulnerability prediction dataset with security-related metrics that have a strong indication of vulnerability. The correlation coefficient values of the primary dataset are compared to a benchmark dataset, and a random forest model is built using both datasets. The results demonstrate that the VPM dataset, which includes security-related metrics and code smell metrics in addition to traditional software metrics, exhibits higher correlation values to vulnerability. The inclusion of securityrelated metrics significantly improves the performance of VPMs, achieving precision, recall, and f-measure above 90% in within-project prediction and over 80% in cross-project prediction. The study concludes that the addition of security-related metrics and code smells to traditional software metrics in the dataset enhances the performance of VPMs.
Title: Empirical Validation of Software Metrics for Software Security Vulnerability Prediction
Description:
The increasing vulnerability of software systems and the potential for significant damages caused by security flaws necessitate the prediction of vulnerable components before deployment.
Existing Vulnerability Prediction Models (VPMs) have not achieved an acceptable threshold for cross-project prediction performance, often sacrificing traceability for accuracy.
Static analyzers suffer from false positives and false negatives.
This study aims to create a software vulnerability prediction dataset with security-related metrics that have a strong indication of vulnerability.
The correlation coefficient values of the primary dataset are compared to a benchmark dataset, and a random forest model is built using both datasets.
The results demonstrate that the VPM dataset, which includes security-related metrics and code smell metrics in addition to traditional software metrics, exhibits higher correlation values to vulnerability.
The inclusion of securityrelated metrics significantly improves the performance of VPMs, achieving precision, recall, and f-measure above 90% in within-project prediction and over 80% in cross-project prediction.
The study concludes that the addition of security-related metrics and code smells to traditional software metrics in the dataset enhances the performance of VPMs.
Related Results
Information Security in Artificial Intelligence: A Study of the possible intersection
Information Security in Artificial Intelligence: A Study of the possible intersection
1. IntroductionArtificial Intelligence or A.I attempts to understand intelligent entities, and strives to build ones. And it is obvious that computers with human-level intelligence...
THE SECURITY AND PRIVACY MEASURING SYSTEM FOR THE INTERNET OF THINGS DEVICES
THE SECURITY AND PRIVACY MEASURING SYSTEM FOR THE INTERNET OF THINGS DEVICES
The purpose of the article: elimination of the gap in existing need in the set of clear and objective security and privacy metrics for the IoT devices users and manufacturers and a...
Validation in Doctoral Education: Exploring PhD Students’ Perceptions of Belonging to Scaffold Doctoral Identity Work
Validation in Doctoral Education: Exploring PhD Students’ Perceptions of Belonging to Scaffold Doctoral Identity Work
Aim/Purpose: The aim of this article is to make a case of the role of validation in doctoral education. The purpose is to detail findings from three studies which explore PhD stude...
Next steps in capturing vulnerability dynamics: Introducing a connectivity-based model on systemic vulnerability to multi-hazards
Next steps in capturing vulnerability dynamics: Introducing a connectivity-based model on systemic vulnerability to multi-hazards
Vulnerability has been acknowledged as a dynamic concept since the Pressure and Release model of Blaikie et al. (1994), as well as by other well-known models that integrate this ri...
A catalog of metrics at source code level for vulnerability prediction: A systematic mapping study
A catalog of metrics at source code level for vulnerability prediction: A systematic mapping study
AbstractIndustry practitioners assess software from a security perspective to reduce the risks of deploying vulnerable software. Besides following security best practice guidelines...
Actionable Insights from Developer Behavior: A Practical Approach to Software Defect Prediction
Actionable Insights from Developer Behavior: A Practical Approach to Software Defect Prediction
Abstract
Software defect prediction using code metrics has been extensively researched over the past five decades. However, prediction using non-software metrics remains un...
Development Tasks of AI-based Security Industry
Development Tasks of AI-based Security Industry
Recently, the government's interest in industries utilizing AI has been amplified, with initiatives such as announcing a roadmap aiming to achieve the goal of becoming the world's ...
ESSENTIAL SECURITY PRACTICES FOR FORTIFYING MOBILE APPS
ESSENTIAL SECURITY PRACTICES FOR FORTIFYING MOBILE APPS
“Essential Security Practices for Fortifying Mobile Apps” is a definitive guide designed to empower developers, security professionals, and organizations with the knowledge and too...

