A Clairvoyant Approach to Evaluating Software (In)Security

Bhushan Jain, Chia-Che Tsai, Donald E. Porter · 2017

Nearly all modern software has security flaws---either known or unknown by the users. However, metrics for evaluating software security (or lack thereof) are noisy at best. Common evaluation methods include counting the past vulnerabilities of the program, or comparing the size of the Trusted Computing Base (TCB), measured in lines of code (LoC) or binary size. Other than deleting large swaths of code from project, it is difficult to assess whether a code change decreased the likelihood of a future security vulnerability. Developers need a practical, constructive way of evaluating security.

Read the paper · More papers on PaperTik