VULNERLIZER: Cross-analysis Between Vulnerabilities and Software Libraries

dc.contributor.authorPekaric, Irdin
dc.contributor.authorFelderer, Michael
dc.contributor.authorSteinmüller, Philipp
dc.date.accessioned2020-12-24T20:27:47Z
dc.date.available2020-12-24T20:27:47Z
dc.date.issued2021-01-05
dc.description.abstractThe identification of vulnerabilities is a continuous challenge in software projects. This is due to the evolution of methods that attackers employ as well as the constant updates to the software, which reveal additional issues. As a result, new and innovative approaches for the identification of vulnerable software are needed. In this paper, we present VULNERLIZER, which is a novel framework for cross-analysis between vulnerabilities and software libraries. It uses CVE and software library data together with clustering algorithms to generate links between vulnerabilities and libraries. In addition, the training of the model is conducted in order to reevaluate the generated associations. This is achieved by updating the assigned weights. Finally, the approach is then evaluated by making the predictions using the CVE data from the test set. The results show that the VULNERLIZER has a great potential in being able to predict future vulnerable libraries based on an initial input CVE entry or a software library. The trained model reaches a prediction accuracy of 75% or higher.
dc.format.extent10 pages
dc.identifier.doi10.24251/HICSS.2021.843
dc.identifier.isbn978-0-9981331-4-0
dc.identifier.urihttp://hdl.handle.net/10125/71464
dc.language.isoEnglish
dc.relation.ispartofProceedings of the 54th Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectCybersecurity and Software Assurance
dc.subjectdata mining
dc.subjectsoftware library analysis
dc.subjectsoftware security
dc.subjectsoftware vulnerability prediction
dc.subjectvulnerability analysis
dc.titleVULNERLIZER: Cross-analysis Between Vulnerabilities and Software Libraries
prism.startingpage7015

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
0686.pdf
Size:
445.63 KB
Format:
Adobe Portable Document Format