Published September 24, 2020 | Version v1
Journal article Open

Technical debt as an indicator of software security risk: a machine learning approach for software development enterprises

  • 1. Centre for Research and Technology Hellas, Information Technologies Institute, Thessaloniki, Greece

Description

Vulnerability prediction facilitates the development of secure soft-ware, as it enables the identification and mitigation of security risks early enough in the software development lifecycle. Although sev-eral factors have been studied for their ability to indicate software security risk, very limited attention has been given to technical debt (TD), despite its potential relevance to software security. To this end, in the present study, we investigate the ability of common TD indicators to indicate security risks in software products, both at project-level and at class-level of granularity. Our findings suggest that TD indicators may potentially act as security indicators as well.

Files

10.1080@17517575.2020.1824017.pdf

Files (2.1 MB)

Name Size Download all
md5:fdf80b0b4fbfa662a997dd41ec6c3e3b
2.1 MB Preview Download

Additional details

Funding

SDK4ED – Software Development toolKit for Energy optimization and technical Debt elimination 780572
European Commission