Software Security Economics: Theory, in Practice
An Exploratory Analysis
Stephan Neuhaus<neuhaust@tik.ee.ethz.ch> Bernhard Plattner <plattner@tik.ee.ethz.ch>
Thursday, June 28, 12
Software Security Economics: Theory, in Practice An Exploratory - - PowerPoint PPT Presentation
Software Security Economics: Theory, in Practice An Exploratory Analysis Stephan Neuhaus<neuhaust@tik.ee.ethz.ch> Bernhard Plattner <plattner@tik.ee.ethz.ch> Thursday, June 28, 12 Making the Best Use of Cybersecurity Economic
An Exploratory Analysis
Stephan Neuhaus<neuhaust@tik.ee.ethz.ch> Bernhard Plattner <plattner@tik.ee.ethz.ch>
Thursday, June 28, 12
Rachel Rue and Shari Lawrence Pfleeger. Making the best use of cybersecurity economic models. IEEE Security & Privacy, 7:52–60, 2009.
Thursday, June 28, 12
Cumulative Investment Security
Thursday, June 28, 12
Thursday, June 28, 12
Thursday, June 28, 12
Thursday, June 28, 12
Thursday, June 28, 12
Thursday, June 28, 12
Thursday, June 28, 12
Image source: Mozilla foundation
Thursday, June 28, 12
Image source: Apache foundation
Thursday, June 28, 12
Image source: Apache foundation
Thursday, June 28, 12
Vulnerability Fix Checkins (Mozilla)
Checkins
5 10 15 2001 2002 2003 2004 2005 2006 2007 2008 2009 2010 2011
Thursday, June 28, 12
Thursday, June 28, 12
Average Vulnerability Fix Checkins (Combined)
Average Checkins per Day
0.003 0.01 0.03 0.1 0.3 1 2002 2003 2004 2005 2006 2007 2008 2009 2010 2011 Product Mozilla Httpd Tomcat
Thursday, June 28, 12
Average Vulnerability Fix Checkins (Combined)
Average Checkins per Day
0.003 0.01 0.03 0.1 0.3 1 2002 2003 2004 2005 2006 2007 2008 2009 2010 2011 Product Mozilla Httpd Tomcat
Move to different repository, way fewer checkins, higher percentage
Thursday, June 28, 12
Average Vulnerability Fix Checkins (Combined)
Average Checkins per Day
0.003 0.01 0.03 0.1 0.3 1 2002 2003 2004 2005 2006 2007 2008 2009 2010 2011 Product Mozilla Httpd Tomcat
Thursday, June 28, 12
Average Vulnerability Fix Checkins (Combined)
Average Checkins per Day
0.003 0.01 0.03 0.1 0.3 1 2002 2003 2004 2005 2006 2007 2008 2009 2010 2011 Product Mozilla Httpd Tomcat
Thursday, June 28, 12
Average Vulnerability Fix Checkins (Combined)
Average Checkins per Day
0.003 0.01 0.03 0.1 0.3 1 2002 2003 2004 2005 2006 2007 2008 2009 2010 2011 Product Mozilla Httpd Tomcat
Thursday, June 28, 12
Number of Committers (Combined)
Average Checkins per Day
1 3 10 30 2001 2002 2003 2004 2005 2006 2007 2008 2009 2010 2011 Product Mozilla Httpd Tomcat
Thursday, June 28, 12
Thursday, June 28, 12
Thursday, June 28, 12
Thursday, June 28, 12
Thursday, June 28, 12
Thursday, June 28, 12
Checkins per Day Days
100 101 102 103
2 3 4 5 6 7 8 9 10 11 13 15 1 2 3 5 1 2 Product
Mozilla Tomcat
Thursday, June 28, 12
Neil Johnson, Spencer Carran, Joel Botner, Kyle Fontaine, Nathan Laxague, Philip Nuetzel, Jessica Turnley, and Brian Tivnan. Pattern in escalations in insurgent and terrorist
Thursday, June 28, 12
Thursday, June 28, 12
Thursday, June 28, 12
Thursday, June 28, 12