Security Trend Analysis with CVE Topic Models

dc.contributor.authorNeuhaus, Stephaneng
dc.contributor.authorZimmermann, Thomaseng
dc.date.accessioned2010-08-13T16:35:56Z
dc.date.available2010-08-13T16:35:56Z
dc.date.issued2010-08-13T16:35:56Z
dc.description.abstractWe study the vulnerability reports in the Common Vulnerability and Exposures (CVE) database by using topic models on their description texts to find prevalent vulnerability types and new trends semi-automatically. In our study of the 39,393 unique CVEs until the end of 2009, we identify the following trends, given here in the form of a weather forecast: PHP: declining, with occasional SQL injection. Buffer Overflows: flattening out after decline. Format Strings: in steep decline. SQL Injection and XSS: remaining strong, and rising. Cross-Site Request Forgery: a sleeping giant perhaps, stirring. Application Servers: rising steeply.eng
dc.description.refereedNoeng
dc.identifier.department2010-970-19eng
dc.identifier.doihttp://dx.doi.org/10.11575/PRISM/31260
dc.identifier.urihttp://hdl.handle.net/1880/48066
dc.language.isoengeng
dc.publisher.corporateUniversity of Calgaryeng
dc.publisher.facultyScienceeng
dc.subjectSecurityeng
dc.subject.otherSecurity, trends, machine learningeng
dc.titleSecurity Trend Analysis with CVE Topic Modelseng
dc.typetechnical reporteng
thesis.degree.disciplineComputer Scienceeng
Files
Original bundle
Now showing 1 - 2 of 2
Loading...
Thumbnail Image
Name:
2010-970-19.pdf
Size:
808.19 KB
Format:
Adobe Portable Document Format
No Thumbnail Available
Name:
2010_970_19_ZIP.zip
Size:
12.3 MB
Format:
Unknown data format
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.86 KB
Format:
Item-specific license agreed upon to submission
Description: