Workshop · 2013
Dismal Code: Studying the Evolution of Security Bugs
Dimitris Mitropoulos, Vassilios Karakoidas, Panos Louridas, Georgios Gousios, Diomidis Spinellis
An empirical study of how security bugs behave as software evolves, across every version of every Java project in Maven Central — whether they get fixed, whether they track project size, and whether they resemble other defects.
- Published in
- Proceedings of the LASER Workshop 2013, Learning from Authoritative Security Experiment Results, pp. 37--48, 2013
- Citations
- 22 on Google Scholar, read 5 September 2026 — 7 of 30 by count
- Cite as
- MKLGS13
The idea
The hypothesis under test was the comfortable one: that security bugs decrease as a project matures, because they are the defects developers have most reason to remove. The Maven ecosystem — every release of every project, with dependency data — is large enough to check it against real histories rather than a handful of case studies.
What it examined
- How security-bug counts move as a project evolves through its releases.
- Persistence: whether severe bugs sit unresolved for long stretches.
- The relation between security bugs and the size of a release.
- The relation between security bugs and the other FindBugs categories.
- The ecosystem's shape: whether a version that many other projects depend on carries proportionally fewer security bugs.
What it found
No simple rule governs the number of security bugs as a project evolves — across projects, the counts neither rise nor fall significantly. Security bugs are not eliminated in a way that is noticeably different from other bugs. Their relationship with the size of a release does look different from other categories'. And severe security bugs appear unassociated with the other bug categories, even though bugs in general behave alike. The conclusion is an invitation rather than a result: projects have their own idiosyncrasies here, and finding what the projects with worsening security have in common is the next question.
The analysis code is on this site as Dismal Code; the data it ran on is the vulnerability dataset.
Written from the paper itself — the PDF linked above, which this site hosts.