CIVILICA We Respect the Science
(ناشر تخصصی کنفرانسهای کشور / شماره مجوز انتشارات از وزارت فرهنگ و ارشاد اسلامی: ۸۹۷۱)

Secure Environment via Prediction of Software Vulnerabilities-Severity

عنوان مقاله: Secure Environment via Prediction of Software Vulnerabilities-Severity
شناسه ملی مقاله: JR_IJEE-10-2_014
منتشر شده در شماره 2 دوره 10 فصل Spring در سال 1398
مشخصات نویسندگان مقاله:

E. S. Aghaee Meybodi - Computer Engineering Group, Engineering Campus, Yazd University, Yazd, Iran
M. Ghasemzadeh - Computer Engineering Group, Engineering Campus, Yazd University, Yazd, Iran

خلاصه مقاله:
Prediction of software vulnerabilities-severity is of particular importance. Its most important application is that managers can first deal with the most dangerous vulnerabilities when they have limited resources. This research shows how we can use the former patterns of software vulnerabilities-severity along with machine learning methods to predict the vulnerabilities severity of that software in the future. In this regard, we used the SVM, Decision Trees (DT), Random Forests (RF), K Nearest Neighbors (KNN), bagging and AdaBoost algorithms along with the already reported vulnerabilities of Google Android applications, Apple Safari and the Flash Player. The experimental results showed that the Bagging algorithm can predict Google Android vulnerability with accuracy of 78.21% and f1-measure equal to 77%, the vulnerability of the Flash Player software with accuracy of 82.37% and f1-measure equal to 87.73% and predict the vulnerability severity of the Apple Safari with accuracy of  70.58% and f1-measure equal to 70%. The novelty of this research is introduction of a new method for prediction of software vulnerabilities severity.

کلمات کلیدی:
Machine Learning, Pattern Recognition, prediction, Vulnerability Severity

صفحه اختصاصی مقاله و دریافت فایل کامل: https://civilica.com/doc/930177/