Milk or Wine: Does Software Security Improve with Age?
نویسندگان
چکیده
We examine the code base of the OpenBSD operating system to determine whether its security is increasing over time. We measure the rate at which new code has been introduced and the rate at which vulnerabilities have been reported over the last 7.5 years and fifteen versions. We learn that 61% of the lines of code in today’s OpenBSD are foundational: they were introduced prior to the release of the initial version we studied and have not been altered since. We also learn that 62% of reported vulnerabilities were present when the study began and can also be considered to be foundational. We find strong statistical evidence of a decrease in the rate at which foundational vulnerabilities are being reported. However, this decrease is anything but brisk: foundational vulnerabilities have a median lifetime of at least 2.6 years. Finally, we examined the density of vulnerabilities in the code that was altered/introduced in each version. The densities ranged from 0 to 0.033 vulnerabilities reported per thousand lines of code. These densities will increase as more vulnerabilities are reported. ∗This work is sponsored by the I3P under Air Force Contract FA8721-05-0002. Opinions, interpretations, conclusions and recommendations are those of the author(s) and are not necessarily endorsed by the United States Government. †This work was produced under the auspices of the Institute for Information Infrastructure Protection (I3P) research program. The I3P is managed by Dartmouth College, and supported under Award number 2003-TK-TX-0003 from the U.S. Department of Homeland Security, Science and Technology Directorate. Points of view in this document are those of the authors and do not necessarily represent the official position of the U.S. Department of Homeland Security, the Science and Technology Directorate, the I3P, or Dartmouth College. ‡Currently at the University of Cambridge
منابع مشابه
The Security of OpenBSD: Milk or Wine?
This work was produced under the auspices of the Institute for Information Infrastructure Protection (I3P) research program. The I3P is managed by Dartmouth College, and supported under Award number 2003-TK-TX-0003 from the U.S. Department of Homeland Security, Science and Technology Directorate. Points of view in this document are those of the authors and do not necessarily represent the offic...
متن کاملAcquired Port-Wine stain: Report of two cases
Acquired port-wine stain is a rare vascular lesion that mimics a congenital port-wine stain clinically and histologically, but is acquired after birth. A survey on more than 60 reported cases in the literature reveals that most of these cases are idiopathic, but some of the cases developed after physical or mechanical trauma, hormonal changes, chronic sun exposure, and medications (OCP, i...
متن کاملField Data Available at Symantec Research Labs: The Worldwide Intelligence Network Environment (WINE)
The data sets available today are often insufficient for conducting representative experiments or rigorous empirical research. The Worldwide Intelligence Network Environment (WINE) aims to fill this gap by providing access to sampled data feeds, which are used internally at Symantec Research Labs, and by promoting rigorous experimental methods. WINE allows researchers to define reference data s...
متن کاملInvestigation of different commercial fining agents by SDS-PAGE and immunoblot
Allergenic fining agents and processing aids from hen’s egg and cow’s milk used in wine production are hidden allergens and could demonstrate a health threat for allergic persons. Hence, the European parliament adopted Directive 2003/89/EC amending 2000/13/EC to declare ingredients, contaminations and processing aids which are known to trigger allergic reactions. The Amendment Directive 415/200...
متن کاملComparative Studies of Wine Produced from Pawpaw Juice and Coconut Milk Blend at Different Proportions
This study was aimed at establishing the possibility of producing an acceptable wine from the mixture of pawpaw juice and coconut milk in the following proportions; 90:10, 80:20, 70:30, 60:40 and 50:50 respectively. The process of washing, peeling, extraction of juice, amelioration, clarification, sulphiting, pitching, fermentation, clarification, bottling, pasteurization and ageing were applie...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2006