{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,27]],"date-time":"2026-06-27T19:11:56Z","timestamp":1782587516305,"version":"3.54.5"},"reference-count":44,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2011,12,9]],"date-time":"2011-12-09T00:00:00Z","timestamp":1323388800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2013,2]]},"DOI":"10.1007\/s10664-011-9190-8","type":"journal-article","created":{"date-parts":[[2011,12,8]],"date-time":"2011-12-08T00:49:59Z","timestamp":1323305399000},"page":"25-59","source":"Crossref","is-referenced-by-count":168,"title":["Can traditional fault prediction models be used for vulnerability prediction?"],"prefix":"10.1007","volume":"18","author":[{"given":"Yonghee","family":"Shin","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Laurie","family":"Williams","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2011,12,9]]},"reference":[{"issue":"3","key":"9190_CR1","doi-asserted-by":"crossref","first-page":"219","DOI":"10.1016\/j.cose.2006.10.002","volume":"26","author":"OH Alhazmi","year":"2007","unstructured":"Alhazmi OH, Malaiya YK, Ray I (2007) Measuring, analyzing and predicting security vulnerabilities in software systems. Comput Secur 26(3):219\u2013228","journal-title":"Comput Secur"},{"key":"9190_CR2","doi-asserted-by":"crossref","unstructured":"Antoniol G, Ayari K, Penta MD, Khomh F, Gu\u00e9h\u00e9neuc Y-G (Oct. 27\u201330 2008) Is it a bug or an enhancement? A text-based approach to classify change requests. In: 2008 Conference of the Center for Advanced Studies on Collaborative Research, Ontario, Canada.","DOI":"10.1145\/1463788.1463819"},{"key":"9190_CR3","doi-asserted-by":"crossref","unstructured":"Arisholm E, Briand LC (Sep. 21\u201322 2006) Predicting fault-prone components in a Java Legacy System. In: the 2006 ACM\/IEEE International Symposium on Empirical Software Engineering, Rio de Janeiro, Brazil, pp. 8\u201317.","DOI":"10.1145\/1159733.1159738"},{"key":"9190_CR4","doi-asserted-by":"crossref","unstructured":"Arisholm E, Briand LC, Fuglerud M (5\u20139 Nov. 2007) Data mining techniques for building fault-proneness models in telecom Java Software. In: 18th IEEE Int\u2019l Symposium on Software Reliability Engineering (ISSRE\u201907), Trollh\u00e4ttan, Sweden, pp. 215\u2013224.","DOI":"10.1109\/ISSRE.2007.22"},{"issue":"10","key":"9190_CR5","doi-asserted-by":"crossref","first-page":"751","DOI":"10.1109\/32.544352","volume":"22","author":"VR Basili","year":"1996","unstructured":"Basili VR, Briand LC, Melo WL (1996) A validation of object-oriented design metrics as quality indicators. IEEE Trans Software Eng 22(10):751\u2013761","journal-title":"IEEE Trans Software Eng"},{"key":"9190_CR6","doi-asserted-by":"crossref","unstructured":"Crews-Meyer KA, Hudson PF (2004) Landscape complexity and remote classification in Estern Costal Mexico: applications of Landsat-7 ETM+ Data. Geocarto International 19 (1).","DOI":"10.1080\/10106040408542298"},{"issue":"3","key":"9190_CR7","first-page":"343","volume":"47","author":"K Fitzpatrick-Linz","year":"1981","unstructured":"Fitzpatrick-Linz K (1981) Comparison of sampling procedure and data analysis for a Land-Use and Land-Cover Map. Photogramm Eng Rem Sens 47(3):343\u2013351","journal-title":"Photogramm Eng Rem Sens"},{"key":"9190_CR8","doi-asserted-by":"crossref","unstructured":"Gegick M, Rotella P, Williams L (2009) Toward non-security failures as a predictor of security faults and failures. Paper presented at the International Symposium on Engineering Secure Software and Systems, Leuven, Belgium, February 04\u201306.","DOI":"10.1007\/978-3-642-00199-4_12"},{"key":"9190_CR9","doi-asserted-by":"crossref","unstructured":"Gegick M, Williams L, Osborne J, Vouk M (Oct. 27 2008) Prioritizing software security fortification through code-level metrics. In: 4th ACM workshop on Quality of protection, Alexandria, Virginia, pp 31\u201338.","DOI":"10.1145\/1456362.1456370"},{"issue":"7","key":"9190_CR10","doi-asserted-by":"crossref","first-page":"653","DOI":"10.1109\/32.859533","volume":"26","author":"TL Graves","year":"2000","unstructured":"Graves TL, Karr AF, Marron JS, Siy H (2000) Predicting fault incidence using software change history. IEEE Trans Software Eng 26(7):653\u2013661","journal-title":"IEEE Trans Software Eng"},{"key":"9190_CR11","unstructured":"Guo L, Ma Y, Cukic B, Singh H (2004) Robust prediction of fault-proneness by random forests. In: the 15th International Symposium on Software Reliability Engineering (ISSRE\u201904), Saint-Malo, Bretagne, France, pp 417\u2013428."},{"key":"9190_CR12","doi-asserted-by":"crossref","unstructured":"Hassan AE (2009) Predicting faults using the complexity of code changes. In: the 31st International Conference on Software Engineering, pp 78\u201388.","DOI":"10.1109\/ICSE.2009.5070510"},{"key":"9190_CR13","doi-asserted-by":"crossref","unstructured":"Heckman S, Williams L (Oct. 9\u201310 2008) On establishing a benchmark for evaluating static analysis alert prioritization and classification techniques. In: 2nd International Symposium on Empirical Software Engineering and Measurement, Kaiserslautern, Germany, pp 41\u201350.","DOI":"10.1145\/1414004.1414013"},{"key":"9190_CR14","unstructured":"IEEE (1988) IEEE Std 982.1-1988 IEEE standard dictionary of measures to produce reliable software. IEEE Computer Society."},{"key":"9190_CR15","doi-asserted-by":"crossref","unstructured":"Jiang Y, Cukic B, Menzies T (2008a) Can data transformation help in the detection of fault-prone modules? In: Proceedings of the 2008 Workshop on Defects in Large Software Systems (DEFECTS\u201908), Seattle, Washington, pp 16\u201320.","DOI":"10.1145\/1390817.1390822"},{"key":"9190_CR16","unstructured":"Jiang Y, Cukic B, Menzies T (10\u201314 Nov. 2008b) Cost curve evaluation of fault prediction models. In: 19th International Symposium on oftware Reliability Engineering (ISSRE\u201908), pp 197\u2013206."},{"key":"9190_CR17","doi-asserted-by":"crossref","unstructured":"Kamei Y, Monden A, Matsumoto S, Kakimoto T, Matsumoto K (20\u201321 Sept. 2007) The effects of over and under sampling on fault-prone module detection. In: 1st International Symposium on Empirical Software Engineering and Measurement, Madrid, Spain, pp 196\u2013204.","DOI":"10.1109\/ESEM.2007.28"},{"issue":"1","key":"9190_CR18","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1109\/52.476287","volume":"13","author":"TM Khoshgoftaar","year":"1996","unstructured":"Khoshgoftaar TM, Allen EB, Kalaichelvan KS, Goel N (1996) Early quality prediction: a case study in telecommunications. IEEE Software 13(1):65\u201371","journal-title":"IEEE Software"},{"key":"9190_CR19","doi-asserted-by":"crossref","unstructured":"Kim S, Ernst MD (Sep. 3\u20137 2007) Which warnings should i fix first? In: the 6th Joint Meeting of the European Software Engineering Conference and the ACM SIGSOFT Symposium on The Foundations of Software Engineering, pp 45\u201354.","DOI":"10.1145\/1287624.1287633"},{"key":"9190_CR20","doi-asserted-by":"crossref","unstructured":"Kim S, Zimmermann T, E. James Whitehead J, Zeller A (2007) Predicting faults from cached history. In: the 29th International Conference on Software Engineering, pp 489\u2013498.","DOI":"10.1109\/ICSE.2007.66"},{"key":"9190_CR21","unstructured":"Krsul IV (1998) Software vulnerability analysis. PhD dissertation, Purdue University, West Lafayette."},{"issue":"4","key":"9190_CR22","doi-asserted-by":"crossref","first-page":"485","DOI":"10.1109\/TSE.2008.35","volume":"34","author":"S Lessmann","year":"2008","unstructured":"Lessmann S, Baesens B, Mues C, Pietsch S (2008) Benchmarking classification models for software defect prediction: a proposed framework and novel findings. IEEE Trans Software Eng 34(4):485\u2013496","journal-title":"IEEE Trans Software Eng"},{"key":"9190_CR23","doi-asserted-by":"crossref","unstructured":"Mark A. Hall, Holmes G (2003) Benchmarking attribute selection techniques for discrete class data mining. IEEE Trans Knowl Data Eng 15 (3).","DOI":"10.1109\/TKDE.2003.1245283"},{"issue":"4","key":"9190_CR24","doi-asserted-by":"crossref","first-page":"308","DOI":"10.1109\/TSE.1976.233837","volume":"2","author":"TJ McCabe","year":"1976","unstructured":"McCabe TJ (1976) A complexity measure. IEEE Trans Software Eng 2(4):308\u2013320","journal-title":"IEEE Trans Software Eng"},{"key":"9190_CR25","doi-asserted-by":"crossref","unstructured":"Mende T, Koschke R (2009) Revisiting the evaluation of defect prediction models. In: Proceedings of the 5th International Conference on Predictor Models in Software Engineering (PROMISE\u201909), Vancouver, Canada.","DOI":"10.1145\/1540438.1540448"},{"key":"9190_CR26","doi-asserted-by":"crossref","unstructured":"Meneely A, Williams L (November 2009) Secure open source collaboration: an empirical study of Linus\u2019 Law\u201d computer and communications security. In: Computer and Communications Security (CCS), Chicago, IL, pp 453\u2013462.","DOI":"10.1145\/1653662.1653717"},{"issue":"9","key":"9190_CR27","doi-asserted-by":"crossref","first-page":"637","DOI":"10.1109\/TSE.2007.70721","volume":"33","author":"T Menzies","year":"2007","unstructured":"Menzies T, Dekhtyar A, Distefano J, Greenwald J (2007a) Problems with precision: a response to \u201cComments on \u2018Data Mining Static Code Attributes to Learn Defect Predictors\u2019\u201d. IEEE Trans Software Eng 33(9):637\u2013640","journal-title":"IEEE Trans Software Eng"},{"issue":"1","key":"9190_CR28","doi-asserted-by":"crossref","first-page":"2","DOI":"10.1109\/TSE.2007.256941","volume":"33","author":"T Menzies","year":"2007","unstructured":"Menzies T, Greenwald J, Frank A (2007b) Data mining static code attributes to learn defect predictors. IEEE Trans Software Eng 33(1):2\u201313","journal-title":"IEEE Trans Software Eng"},{"issue":"4","key":"9190_CR29","first-page":"doi:10.1007\/s10","volume":"17","author":"T Menzies","year":"2010","unstructured":"Menzies T, Milton Z, Turhan B, Cukic B, Jiang Y, Bener A (2010) Defect prediction from static code feature: current results, limitations, new approaches. Autom Softw Eng 17(4):doi: 10.1007\/s10515-010-0069-5","journal-title":"Autom Softw Eng"},{"key":"9190_CR30","doi-asserted-by":"crossref","unstructured":"Menzies T, Turhan B, Bener A, Gay G, Cukic B, Jiang Y (May 2008) Implications of ceiling effects in defect predictors. In: the 4th International Workshop on Predictor Models in Software Engineering (PROMISE\u2019'08), Leipzig, Germany, pp 47\u201354.","DOI":"10.1145\/1370788.1370801"},{"key":"9190_CR31","doi-asserted-by":"crossref","unstructured":"Nagappan N, Ball T (May 15\u201321 2005) Use of relative code churn measures to predict system defect density. In: the 27th International Conference on Software Engineering, St. Louis, MO, USA, pp 284\u2013292.","DOI":"10.1145\/1062455.1062514"},{"key":"9190_CR32","doi-asserted-by":"crossref","unstructured":"Nagappan N, Ball T, Zeller A (May 20\u201328 2006) Mining metrics to predict component failures. In: the 28th International Conference on Software Engineering, Shanghai, China, pp 452\u2013461.","DOI":"10.1145\/1134285.1134349"},{"key":"9190_CR33","doi-asserted-by":"crossref","unstructured":"Neuhaus S, Zimmermann T, Zeller A (October 29\u2013November 2 2007) Predicting vulnerable software components. In: the 14th ACM Conference on Computer and Communications Security (CCS\u201907), Alexandria, Virginia, USA, pp 529\u2013540.","DOI":"10.1145\/1315245.1315311"},{"key":"9190_CR34","unstructured":"NIST (2002) The economic impacts of inadequate infrastructure for software testing. National Institute of Standards & Technology."},{"issue":"4","key":"9190_CR35","doi-asserted-by":"crossref","first-page":"340","DOI":"10.1109\/TSE.2005.49","volume":"31","author":"TJ Ostrand","year":"2005","unstructured":"Ostrand TJ, Weyuker EJ, Bell RM (2005) Predicting the location and number of faults in large software systems. IEEE Trans Software Eng 31(4):340\u2013355","journal-title":"IEEE Trans Software Eng"},{"key":"9190_CR36","doi-asserted-by":"crossref","unstructured":"Ostrand TJ, Weyuker EJ, Bell RM (July 9\u201312 2007) Automating algorithms for the identification of fault-prone files. In: the 2007 International Symposium on Software Testing and Analysis (ISSTA\u201907), London, UK, pp. 219\u2013227.","DOI":"10.1145\/1273463.1273493"},{"key":"9190_CR37","volume-title":"An introduction to statistical methods and data analysis","author":"RL Ott","year":"2001","unstructured":"Ott RL, Longnecker M (2001) An introduction to statistical methods and data analysis, 5th edn. Duxbury, Pacific Grove","edition":"5"},{"issue":"3","key":"9190_CR38","doi-asserted-by":"crossref","first-page":"130","DOI":"10.1108\/eb046814","volume":"16","author":"MF Porter","year":"1980","unstructured":"Porter MF (1980) An algorithm for suffix stripping. Program 16(3):130\u2013137","journal-title":"Program"},{"key":"9190_CR39","doi-asserted-by":"crossref","unstructured":"Rice D (2007) Geekonomics: The real cost of insecure software. Addison-Wesley Professional,","DOI":"10.1080\/15536548.2007.10855823"},{"key":"9190_CR40","doi-asserted-by":"crossref","unstructured":"Shin Y, Williams L (Oct. 27 2008) Is complexity really the enemy of software security? In: the 4th ACM Workshop on Quality of Protection, Alexandria, Virginia, USA, pp. 47\u201350.","DOI":"10.1145\/1456362.1456372"},{"key":"9190_CR41","doi-asserted-by":"crossref","unstructured":"Shin Y, Meneely A, Williams L (2011) Evaluating complexity, code churn, and developer activity metrics as indicators of software vulnerabilities. IEEE Trans Software Eng.","DOI":"10.1109\/TSE.2010.81"},{"key":"9190_CR42","volume-title":"Data mining: practical machine learning tools and techniques","author":"IH Witten","year":"2005","unstructured":"Witten IH, Frank E (2005) Data mining: practical machine learning tools and techniques, 2nd edn. Morgan Kaufmann Publishers, Boston","edition":"2"},{"key":"9190_CR43","doi-asserted-by":"crossref","unstructured":"Zimmermann T, Nagappan N (10\u201318 May 2008) Predicting defects using network analysis on dependency graphs. In: the 13th International Conference on Software Engineering, pp. 531\u2013540.","DOI":"10.1145\/1368088.1368161"},{"key":"9190_CR44","doi-asserted-by":"crossref","unstructured":"Zimmermann T, Nagappan N, Williams L (Apr. 6\u201311 2010) Searching for a needle in a haystack: predicting security vulnerabilities for Windows Vista. In: 3rd International Conference on Software Testing, Verification and Validation, Paris, France, pp. 421\u2013428.","DOI":"10.1109\/ICST.2010.32"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-011-9190-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10664-011-9190-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-011-9190-8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,20]],"date-time":"2019-06-20T11:06:09Z","timestamp":1561028769000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10664-011-9190-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,12,9]]},"references-count":44,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2013,2]]}},"alternative-id":["9190"],"URL":"https:\/\/doi.org\/10.1007\/s10664-011-9190-8","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011,12,9]]}}}