A Hybrid Approach for Evaluation and Prioritization of Software Vulnerabilities
Vivek Kumar (),
Misbah Anjum (),
Vernika Agarwal () and
P. K. Kapur ()
Additional contact information
Vivek Kumar: University of Delhi
Misbah Anjum: Amity University
Vernika Agarwal: Amity University
P. K. Kapur: Amity University
A chapter in Predictive Analytics in System Reliability, 2023, pp 39-51 from Springer
Abstract:
Abstract A software vulnerability is a technical flaw or glitch in the software which might be exploited to contravene the security policy of the system. The intensity of software vulnerabilities amplifies at an exponential rate, which is a tedious task for software testers. The removal of these vulnerabilities is an important task for software developers. With the constraint on the cost and time limitations, it becomes important to prioritize the software vulnerabilities and identify those vulnerabilities which are most severe. In this study, we have sub-grouped software vulnerability types into two categories: code execution vulnerabilities and improper authentication vulnerabilities. In this view, the present study focuses on assessing the vulnerabilities which are most prone to attacks. The study utilizes a hybrid methodology comprising of the fuzzy Best Worst Method to prioritize the identified software vulnerabilities, followed by a two-way analysis to integrate the opinion of decision-makers. The research findings show that the vulnerabilities that are caused because of improper code execution are more severe than those of authentication error vulnerabilities. The present framework is validated by using the case of an Indian software testing company situated in the National capital region of India.
Keywords: Software vulnerabilities; Multi-criteria decision-making (MCDM); Fuzzy best–worst method (BWM); Two-way analysis (search for similar items in EconPapers)
Date: 2023
References: Add references at CitEc
Citations:
There are no downloads for this item, see the EconPapers FAQ for hints about obtaining it.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:spr:ssrchp:978-3-031-05347-4_3
Ordering information: This item can be ordered from
http://www.springer.com/9783031053474
DOI: 10.1007/978-3-031-05347-4_3
Access Statistics for this chapter
More chapters in Springer Series in Reliability Engineering from Springer
Bibliographic data for series maintained by Sonal Shukla () and Springer Nature Abstracting and Indexing ().