Posted on by Achim D. Brucker, licensed under CC BY-ND 4.0.

Time for Addressing Software Security Issues

Finding and fixing software vulnerabilities has become a major struggle for most software-development companies. While generally without alternative, such fixing efforts are a major cost factor, which is why companies have a vital interest in focusing their secure software development activities such that they obtain an optimal return on this investment.

Thus, investigating which factors have the largest impact on the actual fix time is an important research area. To shed some light on this area, we analyzed the times for fixing security vulnerabilities at SAP. The results of our study have been published in the Journal on Data Science and Engineering (DSEJ) [1].

Supplementary Material


1. Othmane, L. ben, Chehrazi, G., Bodden, E., Tsalovski, P., and Brucker, A. D. “Time for Addressing Software Security Issues: Prediction Models and Impacting FactorsData Science and Engineering (dsej) 2, no. 2 (2017): 107–124. doi:10.1007/s41019-016-0019-8, URL:

Welcome to the blog of the Software Assurance & Security Research Team at The University of Sheffield. We blog regularly news, tips & tricks, as well as fun facts about software assurance, reliability, security, testing, verification, hacking, and logic.

You can also follow us on Twitter: @logicalhacking.




academia appsec bitcoin browserextensions browsersecurity chrome cordova dast devops devsecops event extensions fixeffort floss hol-ocl hol-testgen hybridapps iast industry iot isabelle/hol logic malicous mbst mobile modeling monads ocl opensource owasp research sap sast sdlc secdevops security securityengineering securitytesting staff&positions test&proof testing tips&tricks tools tuos uk verification webinar websecurity


blog whole site