Towards Empirical Evaluation of Software Security Risk
Author(s)
Blessing, Jenny![Thumbnail](/bitstream/handle/1721.1/139005/blessing-jbless-sm-TPP-2021-thesis.pdf.jpg?sequence=3&isAllowed=y)
DownloadThesis PDF (535.1Kb)
Advisor
Weitzner, Daniel J.
Terms of use
Metadata
Show full item recordAbstract
This thesis provides empirical metrics for different vectors for vulnerability introduction, with a particular focus on cryptographic software. Through quantitative analysis of source code and vulnerability metrics from a variety of cryptographic libraries, we arrive at a more precise notion of what types of modifications introduce a higher level of risk into a system. Empirical evidence of the causes of security risk will provide technically-grounded guidance in the ongoing policy debate over exceptional access, enabling the security community to more objectively evaluate proposed exceptional access systems.
Date issued
2021-06Department
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science; Massachusetts Institute of Technology. Institute for Data, Systems, and SocietyPublisher
Massachusetts Institute of Technology