A Pilot Study on Architecture and Vulnerabilities: Lessons Learned
Adriana Sejfia · 2019
Finding and preventing software vulnerabilities re-quires analyzing their root causes. Numerous cases of vulnerabilities are caused by architectural decisions, or lack thereof. Solutions for issues such as user authentication are crafted at the architectural level, and they are linked to many instances of vulnerabilities. Despite this, there are few studies conducted that try to explore the connection between the architectures of systems, their evolution and vulnerabilities. Moreover, there is a gap in empirical knowledge on how to conduct such studies. In this paper, we aim to close that gap by providing guidelines on how to conduct studies that focus on architecture and vulnerabilities by proposing architecture recovery techniques, metrics to represent architecture change, generating representative datasets and ways to interpret results. To do this, we conducted a pilot study with Tomcat and several of its vulnerabilities.