Overview of Root Causes of Software Vulnerabilities - Technical and User-Side Perspectives
Priya Anand · 2016
Software security is equally a shared responsibility of technical experts and clients who deploys the system. When a software receives security assurance upon its product release, security validation of the software is assured. Security compromise may take place by luring authenticate users to exploit the vulnerabilities persists in the system.Vulnerabilities emerging from user side also plays a significant role in determining security assurance of the system. Depending upon the level of software attack surface, potential vulnerability can be injected into the system. Therefore the root causes of software vulnerabilities cannot merely contributed to the technical aspects of mitigation techniques. These increased level of requirements took security experts to a spectrum where users' improper or insecure practices should also be counted while securing a software system. In this paper, I explain about various factors that includes technical and social perspectives that should be taken into consideration with a proper balance to secure a software system. Based on thorough literature review, an in-depth explanation on various information system vulnerabilities and recommended techniques to reduce the attack surfaces of those vulnerabilities are also provided.