A Novel Vulnerability Prediction Model to Predict Vulnerability Loss Based on Probit Regression

Jinkun Geng,Ping Luo
DOI: https://doi.org/10.1007/s11859-016-1162-9
2016-01-01
Wuhan University Journal of Natural Sciences
Abstract:Software vulnerability is always an enormous threat to software security. Quantitative analysis of software vulnerabilities is necessary to the evaluation and improvement of software security. Current vulnerability prediction models mainly focus on predicting the number of vulnerabilities regardless of the seriousness of vulnerabilities, therefore these models are unable to reflect the security level of software accurately. Starting from this, we propose a vulnerability prediction model based on probit regression in this paper. Unlike traditional ones, we measure the seriousness of vulnerability by the loss it causes and aim at predicting the accumulative vulnerability loss rather than the number of vulnerabilities. To validate our model, experiment is carried out on two software — OpenSSL and Xpdf, and the experimental result shows a good performance of our model.
What problem does this paper attempt to address?