中文
相关论文

相关论文: Quantifying Cybersecurity Effectiveness of Softwar…

200 篇论文

Web services are becoming business-critical components, often deployed with critical software bugs that can be maliciously explored. Web vulnerability scanners allow the detection of security vulnerabilities in web services by stressing the…

密码学与安全 · 计算机科学 2022-12-26 Osejobe Ehichoya , Chinwuba Christian Nnaemeka

Any human-designed system can potentially be exploited in ways that its designers did not envision, and information systems or networks using quantum components do not escape this reality. We are presented with a unique but quickly waning…

密码学与安全 · 计算机科学 2024-04-22 Benjamin Blakely , Joaquin Chung , Alec Poczatek , Ryan Syed , Raj Kettimuthu

The unreflected promotion of diversity as a value in social interactions -- including technology-mediated ones -- risks emphasizing the benefits of inclusion at the cost of not recognizing the potential harm from failing to protect…

社会与信息网络 · 计算机科学 2021-09-24 Paula Helm , Loizos Michael , Laura Schelenz

The lack of security in information systems has caused numerous financial and moral losses to several organizations. The organizations have a series of information security measures recommended by literature and international standards.…

Many software analysis techniques attempt to determine whether bugs are reachable, but for security purpose this is only part of the story as it does not indicate whether the bugs found could be easily triggered by an attacker. The recently…

编程语言 · 计算机科学 2022-12-13 Sébastien Bardin , Guillaume Girol

Current frameworks for evaluating security bug severity, such as the Common Vulnerability Scoring System (CVSS), prioritize the ratio of exploitability to impact. This paper suggests that the above approach measures the "known knowns" but…

密码学与安全 · 计算机科学 2025-03-25 Shue Long Chan

In this paper, we explore the challenges of ensuring security and privacy for users from diverse demographic backgrounds. We propose a threat modeling approach to identify potential risks and countermeasures for product inclusion in…

密码学与安全 · 计算机科学 2024-04-25 Dave Kleidermacher , Emmanuel Arriaga , Eric Wang , Sebastian Porst , Roger Piqueras Jover

Regression testing assures software correctness after changes but is resource-intensive. Test Case Prioritisation (TCP) mitigates this by ordering tests to maximise early fault detection. Diversity-based TCP prioritises dissimilar tests,…

软件工程 · 计算机科学 2025-04-18 Islam T. Elgendy , Robert M. Hierons , Phil McMinn

The alarming rise in the quantity of malware in the last few years poses a serious challenge to the security community and requires urgent response. However, current countermeasures seem to be no longer effective. Thus, it is our belief…

密码学与安全 · 计算机科学 2015-01-20 Elzbieta Rzeszutko , Wojciech Mazurczyk

Metrics and frameworks to quantifiably assess security measures have arisen from needs of three distinct research communities - statistical measures from the intrusion detection and prevention literature, evaluation of cyber exercises,…

密码学与安全 · 计算机科学 2019-10-28 Michael D. Iannacone , Robert A. Bridges

Software testing is a critical element of software quality assurance and represents the ultimate review of specification, design and coding. Software testing is the process of testing the functionality and correctness of software by running…

软件工程 · 计算机科学 2010-01-26 S. S. Riaz Ahamed

An agile approach has become very popular over the last decade, which requires good communication and teamwork within teams as well as with outside stakeholders. Therefore, social interaction is central for a software development team to be…

软件工程 · 计算机科学 2019-03-19 Andreas Bäckevik , Erik Tholén , Lucas Gren

This study investigates vulnerabilities in dependencies of sampled open-source software (OSS) projects, the relationship between these and overall project security, and how developers' behaviors and practices influence their mitigation.…

Although it is common for users to select bad passwords that can be easily cracked by attackers, password-based authentication remains the most widely-used method. To encourage users to select good passwords, enterprises often enforce…

密码学与安全 · 计算机科学 2015-12-21 Cem S. Sahin , Robert Lychev , Neal Wagner

Deployment of anti-virus software is a common strategy for preventing and controlling the propagation of computer viruses and worms over a computer network. As the deployment of such programs is often limited due to monetary or operational…

网络与互联网体系结构 · 计算机科学 2024-12-19 Jhonatan Tavori , Hanoch Levy

To build secure software, developers often work together during software development and maintenance to find, fix, and prevent security vulnerabilities. Examining the nature of developer interactions during their security activities…

软件工程 · 计算机科学 2019-07-30 Song Wang , Nachi Nagappan

Cyber resilience is the ability of a system to resist and recover from a cyber attack, thereby restoring the system's functionality. Effective design and development of a cyber resilient system requires experimental methods and tools for…

Due to the ever-increasing security breaches, practitioners are motivated to produce more secure software. In the United States, the White House Office released a memorandum on Executive Order (EO) 14028 that mandates organizations provide…

密码学与安全 · 计算机科学 2023-06-16 Nusrat Zahan , Shohanuzzaman Shohan , Dan Harris , Laurie Williams

Context: Diversity can impact team communication, productivity, cohesiveness, and creativity. Analyzing the existing knowledge about diversity in open source software (OSS) projects can provide directions for future research and raise…

Nowadays, computation is playing an increasingly more important role in the future generation of computer and communication networks, as exemplified by the recent progress in software defined networking (SDN) for wired networks as well as…

网络与互联网体系结构 · 计算机科学 2017-05-10 Kezhi Wang , Kun Yang , Hsiao-Hwa Chen , Lianming Zhang