A1 Refereed original research article in a scientific journal

Modeling the Delivery of Security Advisories and CVEs




AuthorsRuohonen J, Hyrynsalmi S, Leppanen V

PublisherCOMSIS CONSORTIUM

Publication year2017

JournalComputer Science and Information Systems

Journal name in sourceCOMPUTER SCIENCE AND INFORMATION SYSTEMS

Journal acronymCOMPUT SCI INF SYST

Volume14

Issue2

First page 537

Last page555

Number of pages19

ISSN1820-0214

eISSN2406-1018

DOIhttps://doi.org/10.2298/CSIS161010010R

Self-archived copy’s web addresshttps://research.utu.fi/converis/portal/detail/Publication/26884177


Abstract
This empirical paper models three structural factors that are hypothesized to affect the turnaround times between the publication of security advisories and Common Vulnerabilities and Exposures (CVEs). The three structural factors are: (i) software product age at the time of advisory release; (ii) severity of vulnerabilities coordinated; and (iii) amounts of CVEs referenced in advisories. Although all three factors are observed to provide only limited information for statistically predicting the turnaround times in a dataset comprised of Microsoft, openSUSE, and Ubuntu operating system products, the paper outlines new research directions for better understanding the current problems related to vulnerability coordination.

Downloadable publication

This is an electronic reprint of the original article.
This reprint may differ from the original in pagination and typographic detail. Please cite the original version.





Last updated on 2024-26-11 at 18:52