Options
Is newer always better?: The case of vulnerability prediction models
Publikationstyp
Conference Paper
Date Issued
2016-09
Sprache
English
First published in
Number in series
8/9
Start Page
1
End Page
6
Article Number
a26
Citation
International Symposium on Empirical Software Engineering and Measurement 8/9: a26, 1-6 (2016-09-08)
Contribution to Conference
Publisher DOI
Scopus ID
Publisher
ACM
Finding security vulnerabilities in the source code as early as possible is becoming more and more essential. In this respect, vulnerability prediction models have the potential to help the security assurance activities by identifying code locations that deserve the most attention. In this paper, we investigate whether prediction models behave like milk (i.e., they turn with time) or wine (i.e., the improve with time) when used to predict future vulnerabilities. Our findings indicate that the recall values are largely in favor of predictors based on older versions. However, the better recall comes at the price of much higher file inspection ratio values.
Subjects
prediction models
Security vulnerabilities
MLE@TUHH
DDC Class
004: Informatik