Periode24. nov. 2025

Mediebidrag

1

Mediebidrag

  • TitelVulnerability Counts: A Rejoinder
    Grad af anerkendelseInternational
    Mediets navn/udløbCommunications of the ACM
    MedietypeInternet
    Land/OmrådeUSA
    Dato24/11/2025
    BeskrivelseIn their September 2025 Communications Opinion column, “Stop Using Vulnerability Counts to Measure Software Security,” Andrew Meneely and Brandon Keller presented an argument that vulnerability counts should be avoided for making inferences about software security. The argument is not new, and I have raised it previously also myself. With this rejoinder, I wish to add a little more nuance to the argument and the potential ways forward. In what follows, the points raised are based on my own research, but I omit references for brevity: if needed, any interested reader will be able to find the research with little effort.
    URLhttps://cacm.acm.org/opinion/vulnerability-counts-a-rejoinder/
    PersonerJukka Ruohonen