학술논문

A Suite of Metrics for Calculating the Most Significant Security Relevant Software Flaw Types
Document Type
Conference
Source
2020 IEEE 44th Annual Computers, Software, and Applications Conference (COMPSAC) COMPSAC Computers, Software, and Applications Conference (COMPSAC), 2020 IEEE 44th Annual. :511-516 Jul, 2020
Subject
Computing and Processing
General Topics for Engineers
Measurement
Software
Security
Compounds
Taxonomy
Databases
Data structures
Metrics
Software Flaws
Vulnerabilities
Language
Abstract
The Common Weakness Enumeration (CWE) is a prominent list of software weakness types. This list is used by vulnerability databases to describe the underlying security flaws within analyzed vulnerabilities. This linkage opens the possibility of using the analysis of software vulnerabilities to identify the most significant weaknesses that enable those vulnerabilities. We accomplish this through creating mashup views combining CWE weakness taxonomies with vulnerability analysis data. The resulting graphs have CWEs as nodes, edges derived from multiple CWE taxonomies, and nodes adorned with vulnerability analysis information (propagated from children to parents). Using these graphs, we develop a suite of metrics to identify the most significant weakness types (using the perspectives of frequency, impact, exploitability, and overall severity).