Stop Using Vulnerability Counts to Measure Software Security.

This article argues that counting fixed vulnerabilities is a misleading measure of software security, as it ignores the context, effort, and process improvements behind each fix. Vulnerabilities are discovered under varying conditions, influenced by factors such as tool advances, human diligence, an...

Descripción completa

Detalles Bibliográficos
Publicado en:Communications of the ACM Vol. 68; no. 9; pp. 34 - 37
Autores principales: Meneely, Andy, Keller, Brandon
Formato: Artículo
Publicado: Association for Computing Machinery Sep2025
Materias:
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=187620985&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 187620985
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        00010782
        ACM
      jtl: Communications of the ACM
      issn: 00010782
      maglogo: N
    pubinfo:
      dt: Sep2025
      vid: 68
      iid: 9
      pid: 68
      pub: Association for Computing Machinery
    artinfo:
      ui:
        187620985
        10.1145/3718081
      ppf: 34
      ppct: 3
      formats:
      tig:
        atl: Stop Using Vulnerability Counts to Measure Software Security.
      aug:
        au:
          Meneely, Andy
          Keller, Brandon
        affil: Rochester Institute of Technology, Rochester, New York, United States
      su:
        Computer security vulnerabilities
        Computer software security
        Software measurement
        Corporate culture
        Software architecture
        Internet security
      sug:
        subj:
          Computer security vulnerabilities
          Computer software security
          Software measurement
          Corporate culture
          Software architecture
          Internet security
      ab: This article argues that counting fixed vulnerabilities is a misleading measure of software security, as it ignores the context, effort, and process improvements behind each fix. Vulnerabilities are discovered under varying conditions, influenced by factors such as tool advances, human diligence, and changes in APIs, making raw counts insufficient to gauge security. Instead, the authors propose vulnerability recidivism metrics, which track repeated types, modules, or authors associated with vulnerabilities to better assess process effectiveness and ongoing risk. Emphasizing a culture where developers can safely admit mistakes, reflect on them, and improve practices is key to meaningful cybersecurity measurement and improvement.
      pubtype: Periodical
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2025
    holdings:
      @attributes:
        islocal: N