Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

A catalog of metrics at source code level for vulnerability prediction: A systematic mapping study

View through CrossRef
AbstractIndustry practitioners assess software from a security perspective to reduce the risks of deploying vulnerable software. Besides following security best practice guidelines during the software development life cycle, predicting vulnerability before roll‐out is crucial. Software metrics are popular inputs for vulnerability prediction models. The objective of this study is to provide a comprehensive review of the source code‐level security metrics presented in the literature. Our systematic mapping study started with 1451 studies obtained by searching the four digital libraries from ACM, IEEE, ScienceDirect, and Springer. After applying our inclusion/exclusion criteria as well as the snowballing technique, we narrowed down 28 studies for an in‐depth study to answer four research questions pertaining to our goal. We extracted a total of 685 code‐level metrics. For each study, we identified the empirical methods, quality measures, types of vulnerabilities of the prediction models, and shortcomings of the work. We found that standard machine learning models, such as decision trees, regressions, and random forests, are most frequently used for vulnerability prediction. The most common quality measures are precision, recall, accuracy, and ‐measure. Based on our findings, we conclude that the list of software metrics for measuring code‐level security is not universal or generic yet. Nonetheless, the results of our study can be used as a starting point for future studies aiming at improving existing security prediction models and a catalog of metrics for vulnerability prediction for software practitioners.
Title: A catalog of metrics at source code level for vulnerability prediction: A systematic mapping study
Description:
AbstractIndustry practitioners assess software from a security perspective to reduce the risks of deploying vulnerable software.
Besides following security best practice guidelines during the software development life cycle, predicting vulnerability before roll‐out is crucial.
Software metrics are popular inputs for vulnerability prediction models.
The objective of this study is to provide a comprehensive review of the source code‐level security metrics presented in the literature.
Our systematic mapping study started with 1451 studies obtained by searching the four digital libraries from ACM, IEEE, ScienceDirect, and Springer.
After applying our inclusion/exclusion criteria as well as the snowballing technique, we narrowed down 28 studies for an in‐depth study to answer four research questions pertaining to our goal.
We extracted a total of 685 code‐level metrics.
For each study, we identified the empirical methods, quality measures, types of vulnerabilities of the prediction models, and shortcomings of the work.
We found that standard machine learning models, such as decision trees, regressions, and random forests, are most frequently used for vulnerability prediction.
The most common quality measures are precision, recall, accuracy, and ‐measure.
Based on our findings, we conclude that the list of software metrics for measuring code‐level security is not universal or generic yet.
Nonetheless, the results of our study can be used as a starting point for future studies aiming at improving existing security prediction models and a catalog of metrics for vulnerability prediction for software practitioners.

Related Results

Actionable Insights from Developer Behavior: A Practical Approach to Software Defect Prediction
Actionable Insights from Developer Behavior: A Practical Approach to Software Defect Prediction
Abstract Software defect prediction using code metrics has been extensively researched over the past five decades. However, prediction using non-software metrics remains un...
Next steps in capturing vulnerability dynamics: Introducing a connectivity-based model on systemic vulnerability to multi-hazards
Next steps in capturing vulnerability dynamics: Introducing a connectivity-based model on systemic vulnerability to multi-hazards
Vulnerability has been acknowledged as a dynamic concept since the Pressure and Release model of Blaikie et al. (1994), as well as by other well-known models that integrate this ri...
Empirical Validation of Software Metrics for Software Security Vulnerability Prediction
Empirical Validation of Software Metrics for Software Security Vulnerability Prediction
The increasing vulnerability of software systems and the potential for significant damages caused by security flaws necessitate the prediction of vulnerable components before deplo...
Mapping workflow trends in pulsed-field ablation procedures: an international glimpse
Mapping workflow trends in pulsed-field ablation procedures: an international glimpse
Abstract Background As pulsed field ablation (PFA) is increasingly used in the EP lab, the use of mapping, fluoroscopy, and intr...
ANALISIS ALIH KODE DAN CAMPUR KODE PADA FILM “SANG PRAWIRA EPISODE I DAN EPISODE II” KARYA ONET ADITHIA RIZLAN
ANALISIS ALIH KODE DAN CAMPUR KODE PADA FILM “SANG PRAWIRA EPISODE I DAN EPISODE II” KARYA ONET ADITHIA RIZLAN
This study of code switching and code mixing analysis in the film "Sang Prawira Episode I and Episode II" by Onet Adithia Rizlan aims to determine code switching and code mixing se...
Evaluating the Science to Inform the Physical Activity Guidelines for Americans Midcourse Report
Evaluating the Science to Inform the Physical Activity Guidelines for Americans Midcourse Report
Abstract The Physical Activity Guidelines for Americans (Guidelines) advises older adults to be as active as possible. Yet, despite the well documented benefits of physical activi...

Back to Top