Size & Complexity Design Metrics Identification to Predict Software’s Future Attack Surface at Design Stage for Object Oriented Design

Pankaj Pandey, Niket Bhargava · International journal of advanced research in computer science and electronics engineering · 2012

Software security failures are common and a long standing challenge to the research community. We can conceptualize the vulnerability of an application through its attack surface size. A system's attack surface is an indicator of the system’s security. Unfortunately predicting software’s future attack surface size during design phase in earlier stage of software development life cycle (SDLC) is largely missing. Our objective is to investigate the statistical relationship between system’s attack surface with various size and complexity metrics to find a set of size and complexity metrics which is/are best suitable to predict software’s future attack surface early in software development cycle. In this research paper, we investigate whether software design metrics can be utilized as early indicators of system’s future attack surface size. For an experimental setting, nine open-source java-based projects were analyzed. Our experimental results indicate that architectural information from the non-security realm such as design metrics are useful in system’s attack surface size prediction.

Read the paper · More papers on PaperTik