Loading [MathJax]/extensions/MathMenu.js
The Vulnerability Dataset of a Large Software Ecosystem | IEEE Conference Publication | IEEE Xplore

Abstract:

Security bugs are critical programming errors that can lead to serious vulnerabilities in software. Examining their behaviour and characteristics within a software ecosys...Show More

Abstract:

Security bugs are critical programming errors that can lead to serious vulnerabilities in software. Examining their behaviour and characteristics within a software ecosystem can provide the research community with data regarding their evolution, persistence and others. We present a dataset that we produced by applying static analysis to the Maven Central Repository (approximately 265GB of data) in order to detect potential security bugs. For our analysis we used FindBugs, a tool that examines Java bytecode to detect numerous types of bugs. The dataset contains the metrics' results that FindBugs reports for every project version (a JAR) included in the ecosystem. For every version in our data repository, we also store specific metadata, such as the JAR's size, its dependencies and others. Our dataset can be used to produce interesting research results involving security bugs, as we show in specific examples.
Date of Conference: 11-11 September 2014
Date Added to IEEE Xplore: 04 April 2016
ISBN Information:
Conference Location: Wroclaw, Poland

Contact IEEE to Subscribe

References

References is not available for this document.