Exploring the Clustering of Software Vulnerability Disclosure Notifications Across Software Vendors

dc.contributor.authorJukka Ruohonen
dc.contributor.authorJohannes Holvitie
dc.contributor.authorSami Hyrynsalmi
dc.contributor.authorVille Leppänen
dc.contributor.organizationfi=ohjelmistotekniikka|en=Software Engineering|
dc.contributor.organization-code1.2.246.10.2458963.20.71310837563
dc.contributor.organization-code2610302
dc.converis.publication-id18410007
dc.converis.urlhttps://research.utu.fi/converis/portal/Publication/18410007
dc.date.accessioned2022-10-28T14:10:56Z
dc.date.available2022-10-28T14:10:56Z
dc.description.abstract<p>This exploratory empirical paper investigates annual time delays between vulnerability disclosure notifications and acknowledgments by means of network analysis. These delays are approached through a potential clustering effect of vulnerabilities across software vendors. The analysis is based on a projection from bipartite vendor-vulnerability structures to one-mode vendor-vendor networks, while the hypothesized clustering effect is approached with a conventional community detection algorithm. According to the results, (a) vulnerabilities<br />cluster across vendors, (b) which also explains a portion of the time delays, although (c) the clustering is not stable annually. The computed network (d) clusters can be also interpreted by reflecting these against common software security attack surfaces. The ressults can be used to contemplate (e) practical means with<br />which the efficiency of vulnerability disclosure could be improved.<br /></p>
dc.format.pagerange1
dc.format.pagerange8
dc.identifier.eisbn978-1-5090-4320-0
dc.identifier.isbn978-1-5090-4321-7
dc.identifier.issn2161-5322
dc.identifier.olddbid186753
dc.identifier.oldhandle10024/169847
dc.identifier.urihttps://www.utupub.fi/handle/11111/39775
dc.identifier.urlhttp://ieeexplore.ieee.org/document/7945696/
dc.identifier.urnURN:NBN:fi-fe2021042716331
dc.language.isoen
dc.okm.affiliatedauthorRuohonen, Jukka
dc.okm.affiliatedauthorHolvitie, Johannes
dc.okm.affiliatedauthorHyrynsalmi, Sami
dc.okm.affiliatedauthorLeppänen, Ville
dc.okm.discipline113 Computer and information sciencesen_GB
dc.okm.discipline113 Tietojenkäsittely ja informaatiotieteetfi_FI
dc.okm.internationalcopublicationnot an international co-publication
dc.okm.internationalityInternational publication
dc.okm.typeA4 Conference Article
dc.publisher.countryUnited Statesen_GB
dc.publisher.countryYhdysvallat (USA)fi_FI
dc.publisher.country-codeUS
dc.publisher.placeNew York
dc.relation.conferenceInternational Conference on Computer Systems and Applications
dc.source.identifierhttps://www.utupub.fi/handle/10024/169847
dc.titleExploring the Clustering of Software Vulnerability Disclosure Notifications Across Software Vendors
dc.title.bookProceedings of 13th ACS/IEEE International Conference on Computer Systems and Applications AICCSA 2016
dc.year.issued2016

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
vulnet.pdf
Size:
742.18 KB
Format:
Adobe Portable Document Format
Description:
Final draft