Visible to the public Is Newer Always Better?: The Case of Vulnerability Prediction Models

TitleIs Newer Always Better?: The Case of Vulnerability Prediction Models
Publication TypeConference Paper
Year of Publication2016
AuthorsHovsepyan, Aram, Scandariato, Riccardo, Joosen, Wouter
Conference NameProceedings of the 10th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4427-2
Keywordscomposability, prediction models, pubcrawl, Scalability, security vulnerabilities, software assurance
Abstract

Finding security vulnerabilities in the source code as early as possible is becoming more and more essential. In this respect, vulnerability prediction models have the potential to help the security assurance activities by identifying code locations that deserve the most attention. In this paper, we investigate whether prediction models behave like milk (i.e., they turn with time) or wine (i.e., the improve with time) when used to predict future vulnerabilities. Our findings indicate that the recall values are largely in favor of predictors based on older versions. However, the better recall comes at the price of much higher file inspection ratio values.

URLhttp://doi.acm.org/10.1145/2961111.2962612
DOI10.1145/2961111.2962612
Citation Keyhovsepyan_is_2016