Strengthening the Evidence that Attack Surfaces Can Be Approximated with Stack Traces
Laurie A. Williams, Christopher Theisen · NCSU Libraries Repository (North Carolina State University Libraries) · 2015
Proactive security review and test efforts are a necessary component of the software development lifecycle.Resource limitations often preclude reviewing the entire code base.Making informed decisions on what code to review can improve a team's ability to find and remove more vulnerabilities.Automated attack surface approximation is a technique that uses crash dump stack traces to predict what code may contain exploitable vulnerabilities.The goal of this research is to help software development teams prioritize security efforts by approximating the attack surface of a software system via stack trace analysis.We explore the attack surface approximation approach using Firefox stack traces.We also generate a vulnerability prediction model using metrics such as frequency of appearance, code churn, and unique authors.We create an attack surface approximation at the file level, in which the 8.4% of the files that were part of the attack surface approximation contained 72.1% of the vulnerabilities seen for the Firefox product.We observed a recall for vulnerability prediction of 0.8 and a precision of 0.04.We generate a decision tree based on churn, author count, and our attack surface approximation metric to guide practitioners in prioritizing code for security review.These results corroborate previous work that showed crash dump stack traces can be used as a metric to prioritize security efforts.