{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T03:47:22Z","timestamp":1784260042438,"version":"3.55.0"},"reference-count":39,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2017,9,19]],"date-time":"2017-09-19T00:00:00Z","timestamp":1505779200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/100004316","name":"International Business Machines Corporation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100004316","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100009226","name":"National Security Agency","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100009226","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100009226","name":"National Security Agency","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100009226","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2018,6]]},"DOI":"10.1007\/s10664-017-9541-1","type":"journal-article","created":{"date-parts":[[2017,9,19]],"date-time":"2017-09-19T10:30:04Z","timestamp":1505817004000},"page":"1383-1421","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":35,"title":["Are vulnerabilities discovered and resolved like other defects?"],"prefix":"10.1007","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0773-7817","authenticated-orcid":false,"given":"Patrick J.","family":"Morrison","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rahul","family":"Pandita","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xusheng","family":"Xiao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ram","family":"Chillarege","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Laurie","family":"Williams","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,9,19]]},"reference":[{"key":"9541_CR1","doi-asserted-by":"publisher","DOI":"10.1002\/0470114754","volume-title":"An introduction to categorical data analysis, vol 135","author":"A Agresti","year":"2007","unstructured":"Agresti A (2007) An introduction to categorical data analysis, vol 135. Wiley, New York"},{"key":"9541_CR2","unstructured":"Alhazmi O H, Malaiya Y K (2005) Modeling the vulnerability discovery process. In: 16th IEEE international symposium on software reliability engineering, 2005. ISSRE 2005. IEEE, p 10"},{"key":"9541_CR3","unstructured":"Anbalagan P (2011) A study of software security problem disclosure, correction and patching processes. PhD thesis, North Carolina State University"},{"key":"9541_CR4","unstructured":"Basili V R, Rombach H D (1987) Tailoring the software process to project goals and environments. In: Proceedings of ICSE. IEEE, pp 345\u2013357"},{"issue":"1","key":"9541_CR5","doi-asserted-by":"publisher","first-page":"182","DOI":"10.1147\/sj.331.0182","volume":"33","author":"I Bhandari","year":"1994","unstructured":"Bhandari I, Halliday M J, Chaar J, Chillarege R, Jones K, Atkinson J, Lepori-Costello C, Jasper P, Tarver E, Lewis C et al (1994) In-process improvement through defect data interpretation. IBM Syst J 33(1):182\u2013214","journal-title":"IBM Syst J"},{"key":"9541_CR6","volume-title":"Software engineering economics","author":"B Boehm","year":"1981","unstructured":"Boehm B (1981) Software engineering economics. Prentice Hall PTR, Upper Saddle River"},{"issue":"1","key":"9541_CR7","first-page":"1","volume":"3","author":"N Bridge","year":"1998","unstructured":"Bridge N, Miller C (1998) Orthogonal defect classification using defect data to improve software development. Softw Qual 3(1):1\u20138","journal-title":"Softw Qual"},{"issue":"1","key":"9541_CR8","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1147\/sj.411.0031","volume":"41","author":"M Butcher","year":"2002","unstructured":"Butcher M, Munro H, Kratschmer T (2002) Improving software testing via odc: three case studies. IBM Syst J 41(1):31\u201344","journal-title":"IBM Syst J"},{"key":"9541_CR9","doi-asserted-by":"crossref","unstructured":"Camilo F, Meneely A, Nagappan M (2015) Do bugs foreshadow vulnerabilities?: A study of the chromium project. In: Proceedings of the 12th working conference on mining software repositories, MSR \u201915. IEEE Press, Piscataway, pp 269\u2013279","DOI":"10.1109\/MSR.2015.32"},{"key":"9541_CR10","unstructured":"Chillarege R (2006) ODC-a 10x for root cause analysis. Available online at: \n                    http:\/\/www.chillarege.com\/articles\/odc-10x-root-cause-analysis.html"},{"issue":"11","key":"9541_CR11","doi-asserted-by":"publisher","first-page":"943","DOI":"10.1109\/32.177364","volume":"18","author":"R Chillarege","year":"1992","unstructured":"Chillarege R, Bhandari I S, Chaar J K, Halliday M J, Moebus D S, Ray B K, Wong M-Y (1992) Orthogonal defect classification-a concept for in-process measurements. IEEE Trans Softw Eng 18(11):943\u2013956","journal-title":"IEEE Trans Softw Eng"},{"issue":"3","key":"9541_CR12","doi-asserted-by":"publisher","first-page":"294","DOI":"10.1016\/j.sysarc.2010.06.003","volume":"57","author":"I Chowdhury","year":"2011","unstructured":"Chowdhury I, Zulkernine M (2011) Using complexity, coupling, and cohesion metrics as early indicators of vulnerabilities. J Syst Archit 57(3):294\u2013313","journal-title":"J Syst Archit"},{"issue":"4","key":"9541_CR13","doi-asserted-by":"publisher","first-page":"417","DOI":"10.2307\/3001616","volume":"10","author":"WG Cochran","year":"1954","unstructured":"Cochran W G (1954) Some methods for strengthening the common chi-squared tests. Biometrics 10(4):417\u2013451","journal-title":"Biometrics"},{"key":"9541_CR14","volume-title":"Out of the crisis","author":"WE Deming","year":"1986","unstructured":"Deming W E (1986) Out of the crisis. MIT Press, Cambridge"},{"key":"9541_CR15","doi-asserted-by":"crossref","unstructured":"Gegick M, Williams L, Osborne J, Vouk M (2008) Prioritizing software security fortification throughcode-level metrics. In: Proceedings of the 4th ACM workshop on quality of protection, QoP \u201908. ACM. New York, pp 31\u201338","DOI":"10.1145\/1456362.1456370"},{"key":"9541_CR16","volume-title":"The security development lifecycle","author":"M Howard","year":"2009","unstructured":"Howard M, Lipner S (2009) The security development lifecycle. O\u2019Reilly Media, Incorporated, New York"},{"key":"9541_CR17","doi-asserted-by":"crossref","unstructured":"Hunny U, Zulkernine M, Weldemariam K (2013) Osdc: adapting odc for developing more secure software. In: Proceedings of the 28th SAC. ACM, pp 1131\u20131136","DOI":"10.1145\/2480362.2480574"},{"issue":"1","key":"9541_CR18","doi-asserted-by":"publisher","first-page":"159","DOI":"10.2307\/2529310","volume":"33","author":"JR Landis","year":"1977","unstructured":"Landis J R, Koch G G (1977) The measurement of observer agreement for categorical data. Biometrics 33(1):159\u2013174","journal-title":"Biometrics"},{"issue":"12","key":"9541_CR19","doi-asserted-by":"publisher","first-page":"1147","DOI":"10.1109\/TSE.2014.2354037","volume":"40","author":"F Massacci","year":"2014","unstructured":"Massacci F, Nguyen V H (2014) An empirical methodology to evaluate vulnerability discovery models. IEEE Trans Softw Eng 40(12):1147\u20131162","journal-title":"IEEE Trans Softw Eng"},{"key":"9541_CR20","first-page":"195","volume-title":"Lecture Notes in Computer Science","author":"Fabio Massacci","year":"2011","unstructured":"Massacci F, Neuhaus S, Nguyen V H (2011) After-life vulnerabilities: a study on firefox evolution, its vulnerabilities, and fixes. In: Engineering secure software and systems, pp 195\u2013208. Springer, Berlin"},{"issue":"1","key":"9541_CR21","doi-asserted-by":"publisher","first-page":"4","DOI":"10.1147\/sj.291.0004","volume":"29","author":"R Mays","year":"1990","unstructured":"Mays R, Jones C, Holloway G, Studinski D (1990) Experiences with defect prevention. IBM Syst J 29(1):4\u201332","journal-title":"IBM Syst J"},{"key":"9541_CR22","doi-asserted-by":"crossref","unstructured":"McGraw G (2006) Software security: building security in, volume 1. Addison-Wesley Professional","DOI":"10.1109\/ISSRE.2006.43"},{"key":"9541_CR23","doi-asserted-by":"crossref","unstructured":"Neuhaus S, Zimmermann T, Holler C, Zeller A (2007) Predicting vulnerable software components. In: Proceedings of the 14th ACM conference on computer and communications security, CCS \u201907. ACM, New York, pp 529\u2013540","DOI":"10.1145\/1315245.1315311"},{"key":"9541_CR24","unstructured":"Nguyen V H, Massacci F (2013) The (un)reliability of nvd vulnerable versions data: an empirical experiment on google chrome vulnerabilities. In: Proceedings of the 8th ACM SIGSAC symposium on information, computer and communications security, ASIA CCS \u201913. ACM, New York, pp 493\u2013498"},{"key":"9541_CR25","unstructured":"Ott L (1988) An introduction to statistical methods and data analysis. Duxbury Press"},{"key":"9541_CR26","unstructured":"Ozment J A (2007) Vulnerability discovery & software security. PhD thesis, Citeseer"},{"key":"9541_CR27","volume-title":"The capability maturity model: guidelines for improving the software process","author":"MC Paulk","year":"1995","unstructured":"Paulk M C, Weber C V, Curtis B, Chrissis M B (1995) The capability maturity model: guidelines for improving the software process. Addison-Wesley, Reading"},{"key":"9541_CR28","doi-asserted-by":"crossref","unstructured":"Ray B, Posnett D, Filkov V, Devanbu P (2014) A large scale study of programming languages and code quality in github. In: Proceedings of the 22Nd ACM SIGSOFT international symposium on foundations of software engineering, FSE 2014. ACM, New York, pp 155\u2013165","DOI":"10.1145\/2635868.2635922"},{"key":"9541_CR29","doi-asserted-by":"crossref","unstructured":"Riaz M, King J, Slankas J, Williams L (2014) Hidden in plain sight: automatically identifying security requirements from natural language artifacts. In: Proceedings of the 22nd RE. IEEE, pp 183\u2013192","DOI":"10.1109\/RE.2014.6912260"},{"key":"9541_CR30","doi-asserted-by":"crossref","unstructured":"Robinson B, Francis P, Ekdahl F (2008) A defect-driven process for software quality improvement. In: Proceedings of the 2nd ESEM. ACM, pp 333\u2013335","DOI":"10.1145\/1414004.1414072"},{"issue":"2","key":"9541_CR31","doi-asserted-by":"publisher","first-page":"364","DOI":"10.1002\/j.1538-7305.1930.tb00373.x","volume":"9","author":"W Shewhart","year":"1930","unstructured":"Shewhart W (1930) Economic quality control of manufactured product. Bell Syst Tech J 9(2):364\u2013389","journal-title":"Bell Syst Tech J"},{"issue":"6","key":"9541_CR32","doi-asserted-by":"publisher","first-page":"772","DOI":"10.1109\/TSE.2010.81","volume":"37","author":"Y Shin","year":"2011","unstructured":"Shin Y, Meneely A, Williams L, Osborne J A (2011) Evaluating complexity, code churn, and developer activity metrics as indicators of software vulnerabilities. IEEE Trans Softw Eng 37(6):772\u2013787","journal-title":"IEEE Trans Softw Eng"},{"key":"9541_CR33","volume-title":"Threat modeling: designing for security","author":"A Shostack","year":"2014","unstructured":"Shostack A (2014) Threat modeling: designing for security. Wiley, New York"},{"key":"9541_CR34","doi-asserted-by":"crossref","unstructured":"Souza R, Silva B (2017) Sentiment analysis of travis ci builds. In: Proceedings of the 14th international conference on mining software repositories, MSR \u201917. IEEE Press, Piscataway, pp 459\u2013462","DOI":"10.1109\/MSR.2017.27"},{"key":"9541_CR35","doi-asserted-by":"crossref","unstructured":"Syed-Mohamad S M, McBride T (2008) A comparison of the reliability growth of open source and in-house software. In: Proceedings of the 15th APSEC. IEEE, pp 229\u2013236","DOI":"10.1109\/APSEC.2008.20"},{"key":"9541_CR36","doi-asserted-by":"crossref","unstructured":"Theisen C, Herzig K, Morrison P, Murphy B, Williams L A (2015) Approximating attack surfaces with stack traces. In: 37th IEEE\/ACM international conference on software engineering, ICSE 2015, Florence, Italy, May 16\u201324, vol 2. IEEE, pp 199\u2013208","DOI":"10.1109\/ICSE.2015.148"},{"key":"9541_CR37","doi-asserted-by":"crossref","unstructured":"Walden J, Stuckman J, Scandariato R (2014) Predicting vulnerable components: software metrics vs text mining. In: 2014 IEEE 25th international symposium on software reliability engineering, pp 23\u201333","DOI":"10.1109\/ISSRE.2014.32"},{"key":"9541_CR38","doi-asserted-by":"crossref","unstructured":"Zaman S, Adams B, Hassan A E (2011) Security versus performance bugs: a case study on firefox. In: Proceedings of the 8th working conference on mining software repositories, MSR \u201911. ACM, New York, pp 93\u2013102","DOI":"10.1145\/1985441.1985457"},{"issue":"4","key":"9541_CR39","doi-asserted-by":"publisher","first-page":"240","DOI":"10.1109\/TSE.2006.38","volume":"32","author":"J Zheng","year":"2006","unstructured":"Zheng J, Williams L, Nagappan N, Snipes W, Hudepohl J P, Vouk M A (2006) On the value of static analysis for fault detection in software. IEEE Trans Softw Eng 32(4):240\u2013253","journal-title":"IEEE Trans Softw Eng"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10664-017-9541-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-017-9541-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-017-9541-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,22]],"date-time":"2019-09-22T18:41:10Z","timestamp":1569177670000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10664-017-9541-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,9,19]]},"references-count":39,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2018,6]]}},"alternative-id":["9541"],"URL":"https:\/\/doi.org\/10.1007\/s10664-017-9541-1","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,9,19]]},"assertion":[{"value":"19 September 2017","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}