Concepedia

Abstract

Security researchers are applying software reliability models to vulnerability data, in an attempt to model the vulnerability discovery process. I show that most current work on these vulnerability discovery models (VDMs) is theoretically unsound. I propose a standard set of definitions relevant to measuring characteristics of vulnerabilities and their discovery process. I then describe the theoretical requirements of VDMs and highlight the shortcomings of existing work, particularly the assumption that vulnerability discovery is an independent process.

References

YearCitations

2004

5.1K

2002

2.5K

1998

288

2005

270

2000

263

1999

231

2006

163

2005

121

2006

120

2000

104

Page 1