首页> 外文会议>International Conference on Human System Interaction >Mining Bug Databases for Unidentified Software Vulnerabilities
【24h】

Mining Bug Databases for Unidentified Software Vulnerabilities

机译:用于未认定的软件漏洞的挖掘错误数据库

获取原文

摘要

Identifying software vulnerabilities is becoming more important as critical and sensitive systems increasingly rely on complex software systems. It has been suggested in previous work that some bugs are only identified as vulnerabilities long after the bug has been made public. These vulnerabilities are known as hidden impact vulnerabilities. This paper discusses existing bug data mining classifiers and present an analysis of vulnerability databases showing the necessity to mine common publicly available bug databases for hidden impact vulnerabilities. We present a vulnerability analysis from January 2006 to April 2011 for two well known software packages: Linux kernel and MySQL. We show that 32% (Linux) and 62% (MySQL) of vulnerabilities discovered in this time period were hidden impact vulnerabilities. We also show that the percentage of hidden impact vulnerabilities has increased from 25% to 36% in Linux and from 59% to 65% in MySQL in the last two years. We then propose a hidden impact vulnerability identification methodology based on text mining classifier for bug databases. Finally, we discuss potential challenges faced by a development team when using such a classifier.
机译:识别软件漏洞越来越重要,越来越依赖复杂的软件系统。在以前的工作中提出了一些错误,一些错误仅被识别为漏洞,在公开之后很久就会很长。这些漏洞被称为隐藏的影响漏洞。本文讨论了现有的Bug数据挖掘分类器,并呈现了对漏洞数据库的分析,显示了用于隐藏的影响漏洞的通用公共可用BUG数据库的必要性。我们从2006年1月到2011年4月出现了一个漏洞分析,对于两个众所周知的软件包:Linux内核和MySQL。我们显示在此时间段中发现的32%(Linux)和62%(MySQL)的漏洞是隐藏的影响漏洞。我们还表明隐藏的影响漏洞的百分比从Linux中的25%增加到36%,在过去两年中在MySQL中的59%至65%。然后,我们基于Bug数据库的文本挖掘分类器提出了隐藏的影响漏洞识别方法。最后,我们在使用此类分类器时讨论开发团队面临的潜在挑战。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号