Title
The Vulnerability Dataset of a Large Software Ecosystem
Abstract
Security bugs are critical programming errors that can lead to serious vulnerabilities in software. Examining their behaviour and characteristics within a software ecosystem can provide the research community with data regarding their evolution, persistence and others. We present a dataset that we produced by applying static analysis to the Maven Central Repository (approximately 265GB of data) in order to detect potential security bugs. For our analysis we used FindBugs, a tool that examines Java bytecode to detect numerous types of bugs. The dataset contains the metrics' results that FindBugs reports for every project version (a JAR) included in the ecosystem. For every version in our data repository, we also store specific metadata, such as the JAR's size, its dependencies and others. Our dataset can be used to produce interesting research results involving security bugs, as we show in specific examples.
Year
DOI
Venue
2014
10.1109/BADGERS.2014.8
2014 Third International Workshop on Building Analysis Datasets and Gathering Experience Returns for Security (BADGERS)
Keywords
Field
DocType
Security Bugs,Software Security,Static Analysis,FindBugs,Software Ecosystem,Maven Repository,Software Evolution
Metadata,Computer science,Software security assurance,Java bytecode,Security bug,Software,Information repository,Software evolution,Software ecosystem,Database
Conference
ISBN
Citations 
PageRank 
978-1-4799-8308-7
1
0.35
References 
Authors
0
6
Name
Order
Citations
PageRank
Dimitris Mitropoulos19015.14
Georgios Gousios2133367.86
Panagiotis Papadopoulos3308.42
Vassilios Karakoidas4988.46
Panagiotis Louridas534823.77
Diomidis Spinellis62023178.89