Posted on by Achim D. Brucker, licensed under CC BY-ND 4.0.

Time for Addressing Software Security Issues

Finding and fixing software vulnerabilities has become a major struggle for most software-development companies. While generally without alternative, such fixing efforts are a major cost factor, which is why companies have a vital interest in focusing their secure software development activities such that they obtain an optimal return on this investment.

Thus, investigating which factors have the largest impact on the actual fix time is an important research area. To shed some light on this area, we analysed the times for fixing security vulnerabilities at SAP. The results of our study have been published in the Journal on Data Science and Engineering (DSEJ) [1].

Ben Othmane, L., Chehrazi, G., Bodden, E., Tsalovski, P., & Brucker, A.D. (2016). Time for Addressing Software Security Issues: Prediction Models and Impacting Factors Data Science and Engineering DOI: 10.1007/s41019-016-0019-8

Supplementary Material


1. Othmane, L. ben, Chehrazi, G., Bodden, E., Tsalovski, P., and Brucker, A. D. “Time for Addressing Software Security Issues: Prediction Models and Impacting FactorsData Science and Engineering (dsej) (2016): doi:10.1007/s41019-016-0019-8, URL:

Welcome to the blog of the Software Assurance & Security Research Team at The University of Sheffield. We blog regularly news, tips & tricks, as well as fun facts about software assurance, reliability, security, testing, verification, hacking, and logic.

You can also follow us on Twitter: @logicalhacking.




academia appsec cordova dast devops devsecops fixeffort floss hol-ocl hol-testgen iast industry isabelle/hol logic mbst mobile monads ocl opensource owasp research sap sast sdlc secdevops security securityengineering securitytesting staff&positions test&proof testing tips&tricks tools tuos uk verification


blog whole site