The Vulnerability Dataset of a Large Software Ecosystem

2014 Third International Workshop on Building Analysis Datasets and Gathering Experience Returns for Security (BADGERS)(2014)

引用 4|浏览24
暂无评分
摘要
Security bugs are critical programming errors that can lead to serious vulnerabilities in software. Examining their behaviour and characteristics within a software ecosystem can provide the research community with data regarding their evolution, persistence and others. We present a dataset that we produced by applying static analysis to the Maven Central Repository (approximately 265GB of data) in order to detect potential security bugs. For our analysis we used FindBugs, a tool that examines Java bytecode to detect numerous types of bugs. The dataset contains the metrics' results that FindBugs reports for every project version (a JAR) included in the ecosystem. For every version in our data repository, we also store specific metadata, such as the JAR's size, its dependencies and others. Our dataset can be used to produce interesting research results involving security bugs, as we show in specific examples.
更多
查看译文
关键词
Security Bugs,Software Security,Static Analysis,FindBugs,Software Ecosystem,Maven Repository,Software Evolution
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要