A4 Refereed article in a conference publication

Mining social networks of open source CVE coordination




AuthorsJukka Ruohonen, Sampsa Rauti, Sami Hyrynsalmi, Ville Leppänen

EditorsMiroslaw Staron, Wilhelm Meding

Conference nameInternational Workshop on Software Measurement

Publication year2017

Book title Proceedings of the 27th International Workshop on Software Measurement and 12th International Conference on Software Process and Product Measurement

First page 176

Last page188

Number of pages13

ISBN978-1-4503-4853-9

DOIhttps://doi.org/10.1145/3143434.3143458

Web address https://dl.acm.org/citation.cfm?doid=3143434.3143458


Abstract

Coordination is one central tenet of software engineering practices and processes. In terms of software vulnerabilities, coordination is particularly evident in the processes used for obtaining Common Vulnerabilities and Exposures (CVEs) identifiers for discovered and disclosed vulnerabilities. As the central CVE tracking infrastructure maintained by the non-profit MITRE Corporation has recently been criticized for time delays in CVE assignment, almost an ideal case is available for studying software and security engineering coordination practices with practical relevance. Given this pragmatic motivation, this paper examines open source CVE coordination that occurs on the public oss-security mailing list. By combining social network analysis with a data-driven, exploratory research approach, the paper asks six data mining questions with practical relevance. By contemplating about answers to the questions asked by means of descriptive statistics, the paper consequently contributes not only to the contemporary industry debates, but also to the tradition of empirical vulnerability research. The perspective and the case are both novel in this tradition, thus opening new avenues for further empirical inquiries and practical improvements for the contemporary CVE coordination.



Last updated on 2024-26-11 at 16:32