{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T01:30:25Z","timestamp":1760059825719,"version":"build-2065373602"},"reference-count":26,"publisher":"MDPI AG","issue":"7","license":[{"start":{"date-parts":[[2025,7,14]],"date-time":"2025-07-14T00:00:00Z","timestamp":1752451200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["2409933"],"award-info":[{"award-number":["2409933"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Software attack surfaces define the external boundaries\u2014entry points, communication channels, and sensitive data stores through which adversaries may compromise a system. This paper introduces a scoring mechanism that produces a normalized attack-surface metric in the range of 0\u20131. Building on the established Damage-Potential-to-Effort ratio, our approach further incorporates real-world vulnerability intelligence drawn from MITRE\u2019s CVE and CWE repositories. We compute each application\u2019s score by ingesting preliminary findings from a static-analysis tool and processing them through our unified model. To assess effectiveness, we validate the scoring system across a spectrum of scenarios, from a simple Java application to complex enterprise applications. The resulting metric offers development and security teams a concise, objective measure to monitor an application\u2019s attack surface and hence proactively identify vulnerabilities in their applications. This tool can also be used to benchmark various third-party or dependent applications, enabling both developers and security practitioners to better manage risk.<\/jats:p>","DOI":"10.3390\/fi17070305","type":"journal-article","created":{"date-parts":[[2025,7,15]],"date-time":"2025-07-15T08:04:41Z","timestamp":1752566681000},"page":"305","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Attack Surface Score for Software Systems"],"prefix":"10.3390","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-3571-6875","authenticated-orcid":false,"given":"Yudeep","family":"Rajbhandari","sequence":"first","affiliation":[{"name":"Department of Computer Science, Baylor University, Waco, TX 76706, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-4372-1717","authenticated-orcid":false,"given":"Rokin","family":"Maharjan","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Baylor University, Waco, TX 76706, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sakshi","family":"Shrestha","sequence":"additional","affiliation":[{"name":"Department of Computing, East Tennessee State University, Johnson City, TN 37604, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5882-5502","authenticated-orcid":false,"given":"Tomas","family":"Cerny","sequence":"additional","affiliation":[{"name":"Department of Systems and Industrial Engineering, University of Arizona, Tucson, AZ 85721, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,7,14]]},"reference":[{"key":"ref_1","first-page":"1","article-title":"Effects of Software Security on Software Development Life Cycle and Related Security Issues","volume":"6","author":"Deylami","year":"2015","journal-title":"Int. J. Comput. Intell. Inf. Secur."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Stuckman, J., and Purtilo, J. (2012, January 21). Comparing and Applying Attack Surface Metrics. Proceedings of the 4th International Workshop on Security Measurements and Metrics, MetriSec\u201912, Lund, Sweden.","DOI":"10.1145\/2372225.2372229"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"371","DOI":"10.1109\/TSE.2010.60","article-title":"An Attack Surface Metric","volume":"37","author":"Manadhata","year":"2011","journal-title":"IEEE Trans. Softw. Eng."},{"key":"ref_4","unstructured":"(2025, June 29). Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Moshtari, S., Okutan, A., and Mirakhorli, M. (2021). A Grounded Theory Based Approach to Characterize Software Attack Surfaces. arXiv.","DOI":"10.1145\/3510003.3510210"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"310","DOI":"10.1109\/TDSC.2018.2889086","article-title":"Network Attack Surface: Lifting the Concept of Attack Surface to the Network Level for Evaluating Networks\u2019 Resilience Against Zero-Day Attacks","volume":"18","author":"Zhang","year":"2021","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_7","unstructured":"Atiiq, S.A., Gehrmann, C., Dahl\u00e9n, K., and Khalil, K. (2024). From Generalist to Specialist: Exploring CWE-Specific Vulnerability Detection. arXiv."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Rahaman, M.S., Islam, A., Cerny, T., and Hutton, S. (2023). Static-Analysis-Based Solutions to Security Challenges in Cloud-Native Systems: Systematic Mapping Study. Sensors, 23.","DOI":"10.3390\/s23041755"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Xie, P., Zhang, L., Lian, Z., and Yang, J. (2025). A Network Attack Surface Evaluation Method Based on Optimal Attack Strategy. Electronics, 14.","DOI":"10.3390\/electronics14020274"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Shi, Z., Matyunin, N., Graffi, K., and Starobinski, D. (2024). Uncovering CWE-CVE-CPE Relations with Threat Knowledge Graphs. ACM Trans. Priv. Secur., 27.","DOI":"10.1145\/3641819"},{"key":"ref_11","first-page":"113","article-title":"Tailoring Static Code Analysis for Top 25 CWE in Python","volume":"1","author":"Shihab","year":"2024","journal-title":"Al-Noor J. Inf. Technol. Cyber Secur."},{"key":"ref_12","unstructured":"Nourin, S.M., Karabatis, G., Argiropoulos, F.C., and Measuring Software Security Using Improved CWE Base Scores (2025, June 29). Proceedings of the CIKM 2021 Workshops, Gold Coast, QLD, Australia, 1\u20135 November 2021. Available online: http:\/\/ceur-ws.org\/Vol-3052\/paper16.pdf."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Das, S.S., Serra, E., Halappanavar, M., Pothen, A., and Al-Shaer, E. (2021). V2W-BERT: A Framework for Effective Hierarchical Multiclass Classification of Software Vulnerabilities. arXiv.","DOI":"10.1109\/DSAA53316.2021.9564227"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Fu, M., and Tantithamthavorn, C. (2022, January 23\u201324). LineVul: A Transformer-based Line-Level Vulnerability Prediction. Proceedings of the 2022 IEEE\/ACM 19th International Conference on Mining Software Repositories (MSR), Pittsburgh, PA, USA.","DOI":"10.1145\/3524842.3528452"},{"key":"ref_15","unstructured":"Zhou, Y., Liu, S., Siow, J., Du, X., and Liu, Y. (2019). Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks. Advances in Neural Information Processing Systems 32 (NeurIPS 2019), Curran Associates Inc."},{"key":"ref_16","first-page":"565","article-title":"Static Code Analysis Tools: A Systematic Literature Review","volume":"Volume 31","author":"Dakic","year":"2020","journal-title":"Proceedings of the 31st DAAAM International Symposium"},{"key":"ref_17","unstructured":"Campbell, G.A., and Papapetrou, P.P. (2014). Sonarqube in Action, Manning."},{"key":"ref_18","unstructured":"(2025, June 29). Rules Overview. Available online: https:\/\/docs.sonarqube.org\/latest\/user-guide\/rules\/."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"193","DOI":"10.1016\/j.jss.2014.12.027","article-title":"A systematic mapping study on technical debt and its management","volume":"101","author":"Li","year":"2015","journal-title":"J. Syst. Softw."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Nord, R.L., and Ozkaya, I. (2016, January 3\u20134). Software Vulnerabilities, Defects, and Design Flaws: A Technical Debt Perspective. Proceedings of the 2016 IEEE Cybersecurity Development (SecDev), Boston, MA, USA.","DOI":"10.1109\/SecDev.2016.047"},{"key":"ref_21","unstructured":"DB, K. (2025, June 29). CVE and CWE Mapping Dataset (2021). Available online: https:\/\/www.kaggle.com\/datasets\/krooz0\/cve-and-cwe-mapping-dataset."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Du, Y., and Lu, Y. (2019, January 23\u201325). A Weakness Relevance Evaluation Method Based on PageRank. Proceedings of the 2019 IEEE Fourth International Conference on Data Science in Cyberspace (DSC), Hangzhou, China.","DOI":"10.1109\/DSC.2019.00070"},{"key":"ref_23","unstructured":"Shin, Y., and Williams, L. (2008, January 9\u201310). Evaluating complexity, code churn, and developer activity metrics as indicators of software vulnerabilities. Proceedings of the Second ACM-IEEE International Symposium on Empirical Software Engineering and Measurement, Kaiserslautern, Germany."},{"key":"ref_24","first-page":"44","article-title":"Technical debt in practice: How tools support refactoring","volume":"29","author":"Tom","year":"2013","journal-title":"IEEE Softw."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"618","DOI":"10.1109\/TSE.2010.63","article-title":"What makes a good bug report?","volume":"36","author":"Zimmermann","year":"2010","journal-title":"IEEE Trans. Softw. Eng."},{"key":"ref_26","unstructured":"Siavvas, M. (2019). Static Analysis for Facilitating Secure and Reliable Software. [Ph.D. Thesis, Imperial College London]."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/7\/305\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T18:09:42Z","timestamp":1760033382000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/7\/305"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,14]]},"references-count":26,"journal-issue":{"issue":"7","published-online":{"date-parts":[[2025,7]]}},"alternative-id":["fi17070305"],"URL":"https:\/\/doi.org\/10.3390\/fi17070305","relation":{},"ISSN":["1999-5903"],"issn-type":[{"type":"electronic","value":"1999-5903"}],"subject":[],"published":{"date-parts":[[2025,7,14]]}}}