skip to main content
10.1145/3605770.3625210acmconferencesArticle/Chapter ViewAbstractPublication PagesccsConference Proceedingsconference-collections
extended-abstract

Estimating Security Risk Through Repository Mining

Published:26 November 2023Publication History

ABSTRACT

As open-source projects are becoming ever more present throughout the modern computing stack, it is crucial to be able to quickly spot problematic, poorly maintained, or otherwise "risky" projects. The OSSF Scorecard has been introduced to address this need for fast security risk assessment by mining software repository metadata. We can reasonably expect a project with a CI system, code-reviews, and lots of users to be less risky than a project without those qualities. Since measuring security risk directly is difficult, we test a proxy hypothesis that these factors should also correlate with a reduction of bugs in software and test our hypothesis by scanning thousands of popular C & C++ projects with static analysis tools.

References

  1. Istehad Chowdhury and Mohammad Zulkernine. 2011. Using complexity, coupling, and cohesion metrics as early indicators of vulnerabilities. Journal of Systems Architecture, Vol. 57, 3 (2011), 294--313.Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. Intel. [n.,d.]. Scaling Repo Scanner (SRS). https://github.com/intel/srs.Google ScholarGoogle Scholar
  3. LLVM.org. [n.,d.]. clang-tidy cognitive complexity. https://clang.llvm.org/extra/clang-tidy/checks/readability/function-cognitive-complexity.html.Google ScholarGoogle Scholar
  4. Nuthan Munaiah, Felivel Camilo, Wesley Wigham, Andrew Meneely, and Meiyappan Nagappan. 2017. Do bugs foreshadow vulnerabilities? An in-depth study of the chromium project. Empirical Software Engineering , Vol. 22 (2017), 1305--1347.Google ScholarGoogle ScholarDigital LibraryDigital Library
  5. Yonghee Shin and Laurie Williams. 2008. Is complexity really the enemy of software security?. In Proceedings of the 4th ACM workshop on Quality of protection. 47--50.Google ScholarGoogle ScholarDigital LibraryDigital Library

Index Terms

  1. Estimating Security Risk Through Repository Mining

      Recommendations

      Comments

      Login options

      Check if you have access through your login credentials or your institution to get full access on this article.

      Sign in
      • Published in

        cover image ACM Conferences
        SCORED '23: Proceedings of the 2023 Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses
        November 2023
        111 pages
        ISBN:9798400702631
        DOI:10.1145/3605770

        Copyright © 2023 Owner/Author

        Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

        Publisher

        Association for Computing Machinery

        New York, NY, United States

        Publication History

        • Published: 26 November 2023

        Check for updates

        Qualifiers

        • extended-abstract

        Upcoming Conference

        CCS '24
        ACM SIGSAC Conference on Computer and Communications Security
        October 14 - 18, 2024
        Salt Lake City , UT , USA
      • Article Metrics

        • Downloads (Last 12 months)33
        • Downloads (Last 6 weeks)5

        Other Metrics

      PDF Format

      View or Download as a PDF file.

      PDF

      eReader

      View online with eReader.

      eReader