Regarding the Exponential Growth of Security Vulnerabilities
摘要
Recent trends in cybersecurity have illuminated a concerning reality: the proliferation of security vulnerabilities is undeniably on the rise. Seemingly with a radical trajectory. This study delves into the assertion that the number of security vulnerabilities appears to be escalating exponentially. The emphasis is placed on whether the quantity of security vulnerabilities is experiencing this radical upward trajectory due to a proportional expansion in code length, as the Consortium for Information & Software Quality (CISQ) suggests a correlation between the increase in the number, size, and complexity of software systems and the rise in security vulnerabilities. For the analysis of security vulnerability development, Common Vulnerabilities and Exposures (CVE) are examined. To measure the expansion of code length over the years, the development of Lines of Code (LoC) is evaluated. While the research indicates that the overall CVE development indeed follows an exponential trend, the growth in code length across most analyzed software systems seems to be primarily linear. This indicates that the sharp rise in security vulnerabilities is not proportional to the increase in code length over time and, thus, cannot be solely attributed to it.