All software

Dismal Code: Studying the Evolution of Security Bugs

The LASER 2013 study of how security defects appear, survive and disappear across a project's history.

2012–2013DatasetLASER 2013

A security bug is usually counted once, in the release where somebody found it. This study follows them through time instead: when a defect entered a codebase, how long it stayed, and what its disappearance actually looked like — a deliberate fix, or code being rewritten for unrelated reasons.

The repository holds the analysis code and the paper's own sources. Presented at the LASER workshop in 2013; it is on this site.

Source