Dismal Code: Studying the Evolution of Security Bugs
The LASER 2013 study of how security defects appear, survive and disappear across a project's history.
2012–2013DatasetLASER 2013
A security bug is usually counted once, in the release where somebody found it. This study follows them through time instead: when a defect entered a codebase, how long it stayed, and what its disappearance actually looked like — a deliberate fix, or code being rewritten for unrelated reasons.
The repository holds the analysis code and the paper's own sources. Presented at the LASER workshop in 2013; it is on this site.