Prioritization of Open Source Defects Using Predictive Models
Open AccessThere has been a considerable increase in Open Source software vulnerabilities in recent years (WhiteSource, 2018). Moreover, OSS vulnerabilities are disclosed through nonofficial channels and dispersed among heterogeneous data sources with limited cross-references. This renders efficiently assessing and accurately prioritizing these defects a daunting and impractical task (Snyk, 2019). Researchers have examined the OSS vulnerability assessment by considering crowdsourced information in the form of alerts (Khandpur et al., 2017). However, the potential prioritization of OSS through utilizing disaggregated metrics based on scoring standards available in governmental data sources, such as the National Vulnerability Database (NVD), have not been studied. This study presents a predictive model for OSS vulnerability prioritization based on unstructured descriptive and structured scoring information of OSS vulnerabilities using governmental-based and nongovernmental data sources. The model generates a high-level taxonomy for OSS vulnerability entries and infers associated missing metrics for nongovernmental records. Furthermore, it produces consolidated catalogs as supporting technical references for cybersecurity professionals to facilitate the interrelated assessment and prioritization processes. These catalogs provide cybersecurity professionals with actionable information to make informed decisions by ranking OSS vulnerabilities based on each defect’s vulnerable characteristics, and consequently allow an optimal allocation of resources to remediate the most critical issues.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.
| Thumbnail | Title | Date Uploaded | Visibility | Actions |
|---|---|---|---|---|
|
|
Martinez_gwu_0075A_15281.pdf | 2020-09-10 | Open Access |
|