Estimating Software Vulnerability Counts in the Context of Cyber Risk Assessments
dc.contributor.author | Llanso, Thomas | |
dc.contributor.author | McNeil, Martha | |
dc.date.accessioned | 2017-12-28T02:17:42Z | |
dc.date.available | 2017-12-28T02:17:42Z | |
dc.date.issued | 2018-01-03 | |
dc.description.abstract | Stakeholders often conduct cyber risk assessments as a first step towards understanding and managing their risks due to cyber use. Many risk assessment methods in use today include some form of vulnerability analysis. Building on prior research and combining data from several sources, this paper develops and applies a metric to estimate the proportion of latent vulnerabilities to total vulnerabilities in a software system and applies the metric to five scenarios involving software on the scale of operating systems. The findings suggest caution in interpreting the results of cyber risk methodologies that depend on enumerating known software vulnerabilities because the number of unknown vulnerabilities in large-scale software tends to exceed known vulnerabilities. | |
dc.format.extent | 7 pages | |
dc.identifier.doi | 10.24251/HICSS.2018.687 | |
dc.identifier.isbn | 978-0-9981331-1-9 | |
dc.identifier.uri | http://hdl.handle.net/10125/50576 | |
dc.language.iso | eng | |
dc.relation.ispartof | Proceedings of the 51st Hawaii International Conference on System Sciences | |
dc.rights | Attribution-NonCommercial-NoDerivatives 4.0 International | |
dc.rights.uri | https://creativecommons.org/licenses/by-nc-nd/4.0/ | |
dc.subject | Cyber Security and Software Assurance | |
dc.subject | cyber, discovery rate, flaw rate, risk, vulnerability | |
dc.title | Estimating Software Vulnerability Counts in the Context of Cyber Risk Assessments | |
dc.type | Conference Paper | |
dc.type.dcmi | Text |
Files
Original bundle
1 - 1 of 1