On Mar 18, 2009, at 23:14, Steven M. Christey wrote: > I believe this is reflected in public CVE data. Take a look at the > bugs > that are being reported for, say, Microsoft or major Linux vendors > or most > any product with a long history, and their current number 1's are > not the > same as the number 1's of the past.
I am trying to get funding for a study that would address precisely this issue. Here is a write-up that I made for the Master students here at the University of Trento that explains in more detail what I'm trying to do; perhaps someone on this list is interested in collaborating: http://www.disi.unitn.it/~neuhaus/proposals/Security-Trends.pdf Best, Stephan _______________________________________________ Secure Coding mailing list (SC-L) [email protected] List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l List charter available at - http://www.securecoding.org/list/charter.php SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) as a free, non-commercial service to the software security community. _______________________________________________
