Towards Empirical Evaluation of Software Security Risk
Name
blessing-jbless-sm-TPP-2021-thesis.pdf
Description
Thesis PDF
Size
535.16 KB
Format
Adobe PDF
Checksum (MD5)
c05f19146c9b2bf607d99c79758e6193
Author(s)
Blessing, Jenny
Advisor(s)
Weitzner, Daniel J.
Date Issued
June 2021
Publisher
Massachusetts Institute of Technology
Abstract
This thesis provides empirical metrics for different vectors for vulnerability introduction, with a particular focus on cryptographic software. Through quantitative analysis of source code and vulnerability metrics from a variety of cryptographic libraries, we arrive at a more precise notion of what types of modifications introduce a higher level of risk into a system. Empirical evidence of the causes of security risk will provide technically-grounded guidance in the ongoing policy debate over exceptional access, enabling the security community to more objectively evaluate proposed exceptional access systems.
MIT Department
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Massachusetts Institute of Technology. Institute for Data, Systems, and Society
Terms of Use
In Copyright - Educational Use Permitted
Copyright MIT
Persistent DSpace Link