Modeling the Delivery of Security Advisories and CVEs

dc.contributor.authorRuohonen J
dc.contributor.authorHyrynsalmi S
dc.contributor.authorLeppanen V
dc.contributor.organizationfi=ohjelmistotekniikka|en=Software Engineering|
dc.contributor.organization-code1.2.246.10.2458963.20.71310837563
dc.contributor.organization-code2610302
dc.converis.publication-id26884177
dc.converis.urlhttps://research.utu.fi/converis/portal/Publication/26884177
dc.date.accessioned2022-10-28T13:24:25Z
dc.date.available2022-10-28T13:24:25Z
dc.description.abstractThis empirical paper models three structural factors that are hypothesized to affect the turnaround times between the publication of security advisories and Common Vulnerabilities and Exposures (CVEs). The three structural factors are: (i) software product age at the time of advisory release; (ii) severity of vulnerabilities coordinated; and (iii) amounts of CVEs referenced in advisories. Although all three factors are observed to provide only limited information for statistically predicting the turnaround times in a dataset comprised of Microsoft, openSUSE, and Ubuntu operating system products, the paper outlines new research directions for better understanding the current problems related to vulnerability coordination.
dc.format.pagerange537
dc.format.pagerange555
dc.identifier.eissn2406-1018
dc.identifier.jour-issn1820-0214
dc.identifier.olddbid181863
dc.identifier.oldhandle10024/164957
dc.identifier.urihttps://www.utupub.fi/handle/11111/38923
dc.identifier.urnURN:NBN:fi-fe2021042717245
dc.language.isoen
dc.okm.affiliatedauthorRuohonen, Jukka
dc.okm.affiliatedauthorHyrynsalmi, Sami
dc.okm.affiliatedauthorLeppänen, Ville
dc.okm.discipline113 Computer and information sciencesen_GB
dc.okm.discipline113 Tietojenkäsittely ja informaatiotieteetfi_FI
dc.okm.internationalcopublicationnot an international co-publication
dc.okm.internationalityInternational publication
dc.okm.typeA1 ScientificArticle
dc.publisherCOMSIS CONSORTIUM
dc.publisher.countrySerbiaen_GB
dc.publisher.countrySerbiafi_FI
dc.publisher.country-codeRS
dc.relation.doi10.2298/CSIS161010010R
dc.relation.ispartofjournalComputer Science and Information Systems
dc.relation.issue2
dc.relation.volume14
dc.source.identifierhttps://www.utupub.fi/handle/10024/164957
dc.titleModeling the Delivery of Security Advisories and CVEs
dc.year.issued2017

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
1820-02141700010R.pdf
Size:
702.18 KB
Format:
Adobe Portable Document Format
Description:
Publisher's version