An innovative size-biased multi-version modeling framework for predicting software system vulnerabilities
摘要
Present Software systems are widely utilized in various environments, however, managing and identifying vulnerabilities is more challenging due to the need for periodic upgrades and community-centered development. This paper proposes a novel approach for a multi-version vulnerability prediction model that captures the evolving and interdependent nature of vulnerabilities across software versions, whereas traditional models assume that vulnerabilities are independent across versions, this paper’s approach addresses residual flaws, environment-sensitive weaknesses, and new vulnerabilities introduced through upgrades. A size-biased distribution is utilized to frame the vulnerability detection in the initial version, while future versions are analyzed through a systematic classification of vulnerability sources: first, the vulnerabilities introduced due to new features, second, the environment-sensitive vulnerabilities that arise due to evolving deployment contexts, and last, the residual vulnerabilities from the previous version. The proposed modeling framework addresses not only variations in vulnerability detection rates but also incorporates the dynamic nature of modern software development and version evolution. A statistical analysis has been done using multi-version vulnerability datasets to demonstrate the proposed framework, providing a strong foundation for the research conclusion.