Communication publiée dans un ouvrage (Colloques, congrès, conférences scientifiques et actes)
Vulnerability Prediction Models: A case study on the Linux Kernel
JIMENEZ, Matthieu; PAPADAKIS, Mike; LE TRAON, Yves
2016In 16th IEEE International Working Conference on Source Code Analysis and Manipulation, SCAM 2016, Raleigh, US, October 2-3, 2016
Peer reviewed
 

Documents


Texte intégral
Jimenez_VPMLinuxKernel.pdf
Preprint Auteur (448.8 kB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
Vulnerability Prediction Model; Replication; Linux Kernel
Résumé :
[en] To assist the vulnerability identification process, researchers proposed prediction models that highlight (for inspection) the most likely to be vulnerable parts of a system. In this paper we aim at making a reliable replication and comparison of the main vulnerability prediction models. Thus, we seek for determining their effectiveness, i.e., their ability to distinguish between vulnerable and non-vulnerable components, in the context of the Linux Kernel, under different scenarios. To achieve the above-mentioned aims, we mined vulnerabilities reported in the National Vulnerability Database and created a large dataset with all vulnerable components of Linux from 2005 to 2016. Based on this, we then built and evaluated the prediction models. We observe that an approach based on the header files included and on function calls performs best when aiming at future vulnerabilities, while text mining is the best technique when aiming at random instances. We also found that models based on code metrics perform poorly. We show that in the context of the Linux kernel, vulnerability prediction models can be superior to random selection and relatively precise. Thus, we conclude that practitioners have a valuable tool for prioritizing their security inspection efforts.
Centre de recherche :
ULHPC - University of Luxembourg: High Performance Computing
Disciplines :
Sciences informatiques
Auteur, co-auteur :
JIMENEZ, Matthieu  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
PAPADAKIS, Mike ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
LE TRAON, Yves ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Co-auteurs externes :
no
Langue du document :
Anglais
Titre :
Vulnerability Prediction Models: A case study on the Linux Kernel
Date de publication/diffusion :
octobre 2016
Nom de la manifestation :
16th IEEE International Working Conference on Source Code Analysis and Manipulation
Date de la manifestation :
from 02-10-2016 to 03-10-2016
Manifestation à portée :
International
Titre de l'ouvrage principal :
16th IEEE International Working Conference on Source Code Analysis and Manipulation, SCAM 2016, Raleigh, US, October 2-3, 2016
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
Disponible sur ORBilu :
depuis le 26 août 2016

Statistiques


Nombre de vues
488 (dont 29 Unilu)
Nombre de téléchargements
1679 (dont 20 Unilu)

citations Scopus®
 
35
citations Scopus®
sans auto-citations
32
citations OpenAlex
 
41

Bibliographie


Publications similaires



Contacter ORBilu