Stop Using Vulnerability Counts to Measure Software Security.
This article argues that counting fixed vulnerabilities is a misleading measure of software security, as it ignores the context, effort, and process improvements behind each fix. Vulnerabilities are discovered under varying conditions, influenced by factors such as tool advances, human diligence, an...
| Publicado en: | Communications of the ACM Vol. 68; no. 9; pp. 34 - 37 |
|---|---|
| Autores principales: | , |
| Formato: | Artículo |
| Publicado: |
Association for Computing Machinery
Sep2025
|
| Materias: | |
| Acceso en línea: | Ver este registro en EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=187620985&site=ehost-live header: @attributes: shortDbName: hlh uiTerm: 187620985 longDbName: Humanities International Complete uiTag: AN controlInfo: bkinfo: jinfo: jid: 00010782 ACM jtl: Communications of the ACM issn: 00010782 maglogo: N pubinfo: dt: Sep2025 vid: 68 iid: 9 pid: 68 pub: Association for Computing Machinery artinfo: ui: 187620985 10.1145/3718081 ppf: 34 ppct: 3 formats: tig: atl: Stop Using Vulnerability Counts to Measure Software Security. aug: au: Meneely, Andy Keller, Brandon affil: Rochester Institute of Technology, Rochester, New York, United States su: Computer security vulnerabilities Computer software security Software measurement Corporate culture Software architecture Internet security sug: subj: Computer security vulnerabilities Computer software security Software measurement Corporate culture Software architecture Internet security ab: This article argues that counting fixed vulnerabilities is a misleading measure of software security, as it ignores the context, effort, and process improvements behind each fix. Vulnerabilities are discovered under varying conditions, influenced by factors such as tool advances, human diligence, and changes in APIs, making raw counts insufficient to gauge security. Instead, the authors propose vulnerability recidivism metrics, which track repeated types, modules, or authors associated with vulnerabilities to better assess process effectiveness and ongoing risk. Emphasizing a culture where developers can safely admit mistakes, reflect on them, and improve practices is key to meaningful cybersecurity measurement and improvement. pubtype: Periodical doctype: Article src: R language: English refInfo: copyright: @attributes: flag: Y dt: @attributes: year: 2025 holdings: @attributes: islocal: N |
|---|