Show simple item record

dc.contributor.advisorWeitzner, Daniel J.
dc.contributor.authorBlessing, Jenny
dc.date.accessioned2022-01-14T14:44:05Z
dc.date.available2022-01-14T14:44:05Z
dc.date.issued2021-06
dc.date.submitted2021-06-11T14:54:00.533Z
dc.identifier.urihttps://hdl.handle.net/1721.1/139005
dc.description.abstractThis thesis provides empirical metrics for different vectors for vulnerability introduction, with a particular focus on cryptographic software. Through quantitative analysis of source code and vulnerability metrics from a variety of cryptographic libraries, we arrive at a more precise notion of what types of modifications introduce a higher level of risk into a system. Empirical evidence of the causes of security risk will provide technically-grounded guidance in the ongoing policy debate over exceptional access, enabling the security community to more objectively evaluate proposed exceptional access systems.
dc.publisherMassachusetts Institute of Technology
dc.rightsIn Copyright - Educational Use Permitted
dc.rightsCopyright MIT
dc.rights.urihttp://rightsstatements.org/page/InC-EDU/1.0/
dc.titleTowards Empirical Evaluation of Software Security Risk
dc.typeThesis
dc.description.degreeS.M.
dc.description.degreeS.M.
dc.contributor.departmentMassachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
dc.contributor.departmentMassachusetts Institute of Technology. Institute for Data, Systems, and Society
mit.thesis.degreeMaster
thesis.degree.nameMaster of Science in Technology and Policy
thesis.degree.nameMaster of Science in Electrical Engineering and Computer Science


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record