Which faults are security faults
Michael Gegick, Tao Xie, Laurie A. Williams, Pete Rotella · NCSU Libraries Repository (North Carolina State University Libraries) · 2009
The subtleties associated with security faults can sometimes be missed by developers and testers.When developers encounter a fault and are unaware of the security implications, they are less likely to report it as a security fault to a security team.Security engineers may know the best remediation for a security fault and have the authority to elevate the priority of that fault.Limited resources (e.g., budget, person-hours) preclude a security team from examining all faults in a database to identify which faults are securityrelated.Therefore, an automated means to identify which faults in a fault database are security faults can improve the security assurance of the software.We used SAS Enterprise Miner to automate the textual analysis of fault reports of a Cisco software system in a fault database.We created a predictive model based on a neural network that takes as input the textual description of a fault report and assigns a probability that the fault is security-related.Preliminary results indicate that the model correctly predicted 91.4% of the system's security faults.We applied the model to three other different Cisco software systems and showed that 67% of the security faults were correctly predicted to be security-related.The results indicate that the model is very effective for the system that it was trained on, and is moderately effective for other systems; it may require training on security faults specific to other systems to achieve similar performance.