Published September 24, 2020
| Version v1
Journal article
Open
Technical debt as an indicator of software security risk: a machine learning approach for software development enterprises
Creators
- 1. Centre for Research and Technology Hellas, Information Technologies Institute, Thessaloniki, Greece
Description
Vulnerability prediction facilitates the development of secure soft-ware, as it enables the identification and mitigation of security risks early enough in the software development lifecycle. Although sev-eral factors have been studied for their ability to indicate software security risk, very limited attention has been given to technical debt (TD), despite its potential relevance to software security. To this end, in the present study, we investigate the ability of common TD indicators to indicate security risks in software products, both at project-level and at class-level of granularity. Our findings suggest that TD indicators may potentially act as security indicators as well.
Files
10.1080@17517575.2020.1824017.pdf
Files
(2.1 MB)
Name | Size | Download all |
---|---|---|
md5:fdf80b0b4fbfa662a997dd41ec6c3e3b
|
2.1 MB | Preview Download |