Predicting vulnerable software components with dependency graphs

  • Authors:
  • Viet Hung Nguyen;Le Minh Sang Tran

  • Affiliations:
  • University of Trento, Italy;University of Trento, Italy

  • Venue:
  • Proceedings of the 6th International Workshop on Security Measurements and Metrics
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Security metrics and vulnerability prediction for software have gained a lot of interests from the community. Many software security metrics have been proposed e.g., complexity metrics, cohesion and coupling metrics. In this paper, we propose a novel code metric based on dependency graphs to predict vulnerable components. To validate the efficiency of the proposed metric, we conduct a prediction model which targets the JavaScript Engine of Firefox. In this experiment, our prediction model has obtained a very good result in term of accuracy and recall rates. This empirical result is a good evidence showing dependency graphs are also a good option for early indicating vulnerability.