Skip to main navigation Skip to search Skip to main content

Exploring the clustering of software vulnerability disclosure notifications across software vendors

  • Jukka Ruohonen
  • , Johannes Holvitie
  • , Sami Hyrynsalmi
  • , Ville Leppänen

    Research output: Chapter in Book/Report/Conference proceedingConference contributionScientificpeer-review

    6 Citations (Scopus)

    Abstract

    This exploratory empirical paper investigates annual time delays between vulnerability disclosure notifications and acknowledgments by means of network analysis. These delays are approached through a potential clustering effect of vulnerabilities across software vendors. The analysis is based on a projection from bipartite vendor-vulnerability structures to one-mode vendor-vendor networks, while the hypothesized clustering effect is approached with a conventional community detection algorithm. According to the results, (a) vulnerabilities cluster across vendors, (b) which also explains a portion of the time delays, although (c) the clustering is not stable annually. The computed network (d) clusters can be also interpreted by reflecting these against common software security attack surfaces. The results can be used to contemplate (e) practical means with which the efficiency of vulnerability disclosure could be improved.
    Original languageEnglish
    Title of host publication2016 IEEE/ACS 13th International Conference on Computer Systems and Applications (AICCSA)
    Subtitle of host publicationAgadir, Morocco. Nov. 29 - Dec. 2.2016
    PublisherIEEE
    Pages1-8
    Number of pages8
    ISBN (Electronic)978-1-5090-4320-0
    DOIs
    Publication statusPublished - 12 Jun 2017
    Publication typeA4 Article in conference proceedings
    EventACS/IEEE International Conference of Computer Systems and Applications -
    Duration: 28 Aug 2017 → …

    Publication series

    NameACS/IEEE INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS
    ISSN (Electronic)2161-5330

    Conference

    ConferenceACS/IEEE International Conference of Computer Systems and Applications
    Period28/08/17 → …

    Publication forum classification

    • Publication forum level 1

    Fingerprint

    Dive into the research topics of 'Exploring the clustering of software vulnerability disclosure notifications across software vendors'. Together they form a unique fingerprint.

    Cite this