{"doi":"10.1145/2857705.2857750","title":"To Fear or Not to Fear That is the Question","abstract":null,"journal":"Proceedings of the Sixth ACM Conference on Data and Application Security and Privacy","year":2016,"id":622540,"datarank":0.5837730447165941,"base_score":3.8918202981106265,"endowment":3.8918202981106265,"self_citation_contribution":0.5837730447165941,"citation_network_contribution":0.0,"self_endowment_contribution":0.5837730447165941,"citer_contribution":0.0,"corpus_percentile":null,"corpus_rank":null,"citation_count":48,"citer_count":0,"citers_with_citation_signal":0,"citers_with_endowment":0,"datacite_reuse_total":0,"is_dataset":false,"is_dataset_confidence":null,"is_data_producer":false,"deposit_databanks":null,"is_oa":false,"file_count":0,"downloads":0,"has_version_chain":false,"published_date":null,"fair_score":null,"fair_percentile":null,"algorithm_id":"datarank_citation_only_1hop_v6","ranking_scope":"data_only","authors":[{"id":1608576,"name":"Yashwant Malaiya","orcid":null,"position":1,"is_corresponding":false},{"id":1046130,"name":"Charles Anderson","orcid":"0000-0001-9226-107X","position":2,"is_corresponding":false},{"id":1608577,"name":"Indrajit Ray","orcid":null,"position":3,"is_corresponding":false},{"id":1608575,"name":"Awad Younis","orcid":null,"position":0,"is_corresponding":false}],"reference_count":0,"raw_metadata":{"has_enrichment":true,"resolved":true,"title":"To Fear or Not to Fear That is the Question","abstract":"Not all vulnerabilities are equal. Some recent studies have shown that only a small fraction of vulnerabilities that have been reported has actually been exploited. Since finding and addressing potential vulnerabilities in a program can take considerable time and effort, recently effort has been made to identify code that is more likely to be vulnerable. This paper tries to identify the attributes of the code containing a vulnerability that makes the code more likely to be exploited. We examine 183 vulnerabilities from the National Vulnerability Database for Linux Kernel and Apache HTTP server. These include eighty-two vulnerabilities that have been found to have an exploit according to the Exploit Database. We characterize the vulnerable functions that have no exploit and the ones that have an exploit using eight metrics. The results show that the difference between a vulnerability that has no exploit and the one that has an exploit can potentially be characterized using the chosen software metrics. However, predicting exploitation of vulnerabilities is more complex than predicting just the presence of vulnerabilities and further research is needed using metrics that consider security domain knowledge for enhancing the predictability of vulnerability exploits.","is_dataset_classified":null,"base_score":3.8918202981106265,"endowment":3.8918202981106265,"datacite_reuse_total":0,"file_count":0,"downloads":0,"views":0,"has_version_chain":false,"is_dataset":false,"is_oa":false,"pmid":"19767382","pmcid":null,"openalex_id":"https://openalex.org/W2297096600","authors":[],"funders":[],"total_grants":0,"fwci":3.9308,"citation_percentile":0.95037283,"influential_citations":0,"citation_trend":[{"year":2017,"count":5},{"year":2018,"count":5},{"year":2019,"count":5},{"year":2020,"count":7},{"year":2021,"count":8},{"year":2022,"count":4},{"year":2023,"count":7},{"year":2024,"count":1},{"year":2025,"count":5},{"year":2026,"count":1}],"oa_status":"closed","license":"https://www.acm.org/publications/policies/copyright_policy#Background","oa_locations":[{"url":"https://dl.acm.org/doi/10.1145/2857705.2857750","host_type":"publisher"},{"url":"https://dl.acm.org/doi/pdf/10.1145/2857705.2857750","host_type":"publisher"},{"url":"https://doi.org/10.1145/2857705.2857750","host_type":""}],"fields_of_study":["Software Engineering Research","Software Reliability and Analysis Research","Advanced Malware Detection Techniques"],"mesh_terms":[],"keywords":["Exploit","Computer science","Vulnerability (computing)","Vulnerability management","Security bug","Secure coding","Predictability","Computer security","Code (set theory)","Domain (mathematical analysis)","Vulnerability assessment","Software security assurance","Information security","Set (abstract data type)","Programming language","Security service"],"sdg_mappings":[{"sdg_number":0,"sdg_label":"Reduced inequalities"}],"linked_datasets":[],"clinical_trials":[],"software_tools":[],"database_accessions":[],"source":"live","citation_network_status":"fetched"},"created_at":"2026-08-03T20:00:26.309600Z","pmid":null,"pmcid":null,"fwci":null,"citation_percentile":null,"influential_citations":0,"oa_status":null,"license":null,"views":0,"total_file_size_bytes":0,"version_count":0,"fair_f":null,"fair_a":null,"fair_i":null,"fair_r":null,"fair_zscore":null,"fair_rationale":null,"fair_model":null,"fair_agent_version":null,"fair_fulltext_source":null,"fair_has_llm":null,"fair_computed_at":null,"clinical_trials":[],"software_tools":[],"db_accessions":[],"linked_datasets":[],"topics":[]}