articleIEEE Transactions on Software EngineeringJun 14, 2010Closed access

An Attack Surface Metric

NortonLifeLock (United States) · Carnegie Mellon University

Indexed incrossref

Abstract

Measurement of software security is a long-standing challenge to the research community. At the same time, practical security metrics and measurements are essential for secure software development. Hence, the need for metrics is more pressing now due to a growing demand for secure software. In this paper, we propose using a software system's attack surface measurement as an indicator of the system's security. We formalize the notion of a system's attack surface and introduce an attack surface metric to measure the attack surface in a systematic manner. Our measurement method is agnostic to a software system's implementation language and is applicable to systems of all sizes; we demonstrate our method by…

Citation impact

617
total citations
FWCI
61.36
Percentile
100%
References
88
Citations per year

Authors

2

Topics & keywords

Keywords
  • Attack surface
  • Computer science
  • Software security assurance
  • Software development
  • Software metric
  • Software system
  • Software construction
  • Software engineering
UN Sustainable Development Goals
  • Industry, innovation and infrastructure
No related works found for this paper.