Improving system reliability by optimal allocation of resources for discovering software vulnerabilities
Purpose: The purpose of this paper is to provide a mathematical framework to optimally allocate resources required for the discovery of vulnerabilities pertaining to different severity risk levels. Design/methodology/approach: Different sets of optimization problems have been formulated and using the concept of dynamic programming approach, sequence of recursive functions has been constructed for the optimal allocation of resources used for discovering vulnerabilities of different severity scores. Mozilla Thunderbird web browser data set has been considered for giving the empirical evaluation by working with vulnerabilities of different severities. Findings: As per the impact associated with a vulnerability, critical and high severity level are required to be patched promptly, and hence, a larger amount of funds have to be allocated for vulnerability discovery. Nevertheless, a low or medium risk vulnerability might also get exploited and thereby their discovery is also crucial for higher severity vulnerabilities. The current framework provides a diversified allocation of funds as per the requirement of a software manager and also aims at improving the discovery of vulnerability significantly. Practical implications: The finding of this research may enable software managers to adequately assign resources in managing the discovery of vulnerabilities. It may also help in acknowledging the funds required for various bug bounty programs to cater security reporters based on the potential number of vulnerabilities present in software. Originality/value: Much of the attention has been focused on the vulnerability discovery modeling and the risk associated with the security flaws. But, as far as the authors’ knowledge is concern, there is no such study that incorporates optimal allocation of resources with respect to the vulnerabilities of different severity scores. Hence, the building block of this paper contributes to future research.
Year of publication: |
2019
|
---|---|
Authors: | Bhatt, Navneet ; Anand, Adarsh ; Aggrawal, Deepti |
Published in: |
International Journal of Quality & Reliability Management. - Emerald, ISSN 0265-671X, ZDB-ID 1466792-7. - Vol. 37.2019, 6/7 (22.10.), p. 1113-1124
|
Publisher: |
Emerald |
Saved in:
Online Resource
Saved in favorites
Similar items by person
-
Diffusion Modeling Based on Customer's Review and Product Satisfaction
Singh, Ompal, (2016)
-
Innovation diffusion modeling considering the time lag between awareness and eventual adoption
Anand, Adarsh, (2018)
-
Profit maximization by virtue of price & warranty length optimization
Aggrawal, Deepti, (2014)
- More ...