论文标题
通过数据驱动的方法对软件脆弱性评估的了解深入了解
Towards an Improved Understanding of Software Vulnerability Assessment Using Data-Driven Approaches
论文作者
论文摘要
该论文通过使用数据驱动的方法为软件漏洞评估提供知识和自动化支持来提高软件安全的领域。软件漏洞评估提供了重要且多方面的信息,以预防和减轻野外危险的网络攻击。关键的贡献包括对知识的系统化,以及针对该地区的研究人员和从业人员的一系列新颖的数据驱动技术和实用建议。论文的结果有助于提高理解并为评估现实世界软件系统中不断增加的漏洞的实践提供信息。反过来,这可以更彻底,及时解决这些关键安全问题的优先级和计划。
The thesis advances the field of software security by providing knowledge and automation support for software vulnerability assessment using data-driven approaches. Software vulnerability assessment provides important and multifaceted information to prevent and mitigate dangerous cyber-attacks in the wild. The key contributions include a systematisation of knowledge, along with a suite of novel data-driven techniques and practical recommendations for researchers and practitioners in the area. The thesis results help improve the understanding and inform the practice of assessing ever-increasing vulnerabilities in real-world software systems. This in turn enables more thorough and timely fixing prioritisation and planning of these critical security issues.