lifetimesresearchstatisticsvulnerability-discovery

Alexopoulos et al. — Vulnerability Lifetimes, USENIX Security

Estripically measures the long 'window of exposure' for vulnerabilities in open source and establishes the exponential nature of their discovery process.

Summary

A large-scale study of Free and Open Source Software (FOSS) vulnerability lifetimes found that the average vulnerability remains in the code for approximately 4 years (nearly 1,500 days) before being discovered and fixed. Lifetimes vary significantly by project, ranging from approximately 2 years for Chromium to 7 years for OpenSSL, and are closely correlated with the general code age of the repository. The distribution of lifetimes follows an exponential distribution, with a 'half-life' (median) of 1,040 days. The research found no statistically significant difference in lifetimes between different vulnerability types (e.g., memory management vs. input validation) within the same project, suggesting that discovery order is largely random.

Related Checks

VULN_SLOW_REMEDIATION

The average lifetime of a vulnerability is around 4 years, with a median of 1,040 days, indicating that most vulnerabilities persist in production for years.

Adverse Outcome

extended windows of exposure where systems remain vulnerable to zero-day or long-latent attacks

Because

measuring the duration a vulnerability persists in a codebase identifies projects that lack the proactive security scrutiny needed to reduce discovery lag.

Gaps Analysis

Evidence

Lifetimes are closely correlated with the general code age of a repository. However, vulnerable code lives less than non-vulnerable code.

Blind Spot

Risk Guard does not calculate or display the average age of discovered vulnerabilities (lifetime) relative to the overall age of the codebase.

Actionable Capability

Risk Guard would be better if it provided a 'Code Maturity' score that compared the project's vulnerability discovery rate against its overall code age distribution.

← Previous Next →