Modeling the Delivery of Security Advisories and CVEs

Jukka Ruohonen, Sami Hyrynsalmi, Ville Leppänen

    Research output: Contribution to journalArticleScientificpeer-review

    5 Citations (Scopus)
    10 Downloads (Pure)


    This empirical paper models three structural factors that are hypothesized to affect the turnaround times between the publication of security advisories and Common Vulnerabilities and Exposures (CVEs). The three structural factors are: (i) software product age at the time of advisory release; (ii) severity of vulnerabilities coordinated; and (iii) amounts of CVEs referenced in advisories. Although all three factors are observed to provide only limited information for statistically predicting the turnaround times in a dataset comprised of Microsoft, openSUSE, and Ubuntu operating system products, the paper outlines new research directions for better understanding the current problems related to vulnerability coordination.
    Original languageEnglish
    Pages (from-to)537-555
    JournalComputer Science and Information Systems
    Issue number2
    Early online date10 Mar 2017
    Publication statusPublished - Jun 2017
    Publication typeA1 Journal article-refereed

    Publication forum classification

    • Publication forum level 1


    Dive into the research topics of 'Modeling the Delivery of Security Advisories and CVEs'. Together they form a unique fingerprint.

    Cite this