2026 1st International Conference on Advancing Sustainable Solutions through Technologies (ICASST)(2026)
Department of Mathematics AIAS
被引用0|浏览0
摘要
Unresolved security weaknesses raised serious concerns since they have the potential to allow serious breaches and threaten software system. A vulnerability is a loophole or flaw in a security system that an attacker could take advantage of and cause harm or loss. Since significant portions of code are carried over into subsequent releases, the vulnerabilities may remain and resurface in later versions. These vulnerabilities are often introduced during development as a result of ongoing upgrades and the addition of new features. It is crucial to identify not only when vulnerabilities are introduced but how they are discovered over time because they remain across software generations. A systematic framework for investigating vulnerability discovery trends and forecasting the accumulation of defects has been made available by Vulnerability Discovery Modeling (VDM). However, a large amount of the work that has been done is limited to single-release software, ignoring the impact of shared code and inherited vulnerabilities. In this work, we prefer a multi-version VDM derived from generalized Weibull–logistic distribution. The proposed work intends to examine the impact of vulnerabilities in previous releases and their recurrence in upgraded systems via code inheritance. The model assesses the potential for unfixed vulnerabilities from previous iterations to reappear during new code testing and impact the current release. Real datasets from three distinct Windows Server releases are used to test and validate the model. The prediction performance shows that the newly proposed generalized Weibull-Logistic VDM performs better than existing multi-release VDM. The proposed model offers a more practical framework for evaluating persistent security threats in extensive software ecosystems by incorporating vulnerability inheritance into the discovery process.