<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//TaxonX//DTD Taxonomic Treatment Publishing DTD v0 20100105//EN" "../../nlm/tax-treatment-NS0.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:tp="http://www.plazi.org/taxpub" article-type="research-article" dtd-version="3.0" xml:lang="en">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">109</journal-id>
      <journal-id journal-id-type="index">urn:lsid:arphahub.com:pub:3dc5f44e-8666-58db-bc76-a455210e8891</journal-id>
      <journal-title-group>
        <journal-title xml:lang="en">JUCS - Journal of Universal Computer Science</journal-title>
        <abbrev-journal-title xml:lang="en">jucs</abbrev-journal-title>
      </journal-title-group>
      <issn pub-type="ppub">0948-695X</issn>
      <issn pub-type="epub">0948-6968</issn>
      <publisher>
        <publisher-name>Journal of Universal Computer Science</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.3217/jucs-022-04-0537</article-id>
      <article-id pub-id-type="publisher-id">23125</article-id>
      <article-categories>
        <subj-group subj-group-type="heading">
          <subject>Research Article</subject>
        </subj-group>
        <subj-group subj-group-type="scientific_subject">
          <subject>D.2.0 - General</subject>
          <subject>D.2.8 - Metrics</subject>
          <subject>K.6.5 - Security and Protection</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>An Empirical Investigation of Security Vulnerabilities within Web Applications</article-title>
      </title-group>
      <contrib-group content-type="authors">
        <contrib contrib-type="author" corresp="yes">
          <name name-style="western">
            <surname>Abunadi</surname>
            <given-names>Ibrahim</given-names>
          </name>
          <email xlink:type="simple">iabunadi@psu.edu.sa</email>
          <xref ref-type="aff" rid="A1">1</xref>
        </contrib>
        <contrib contrib-type="author" corresp="no">
          <name name-style="western">
            <surname>Alenezi</surname>
            <given-names>Mamdouh</given-names>
          </name>
          <uri content-type="orcid">https://orcid.org/0000-0001-6852-1206</uri>
          <xref ref-type="aff" rid="A1">1</xref>
        </contrib>
      </contrib-group>
      <aff id="A1">
        <label>1</label>
        <addr-line content-type="verbatim">Prince Sultan University, Riyadh, Saudi Arabia</addr-line>
        <institution>Prince Sultan University</institution>
        <addr-line content-type="city">Riyadh</addr-line>
        <country>Saudi Arabia</country>
      </aff>
      <author-notes>
        <fn fn-type="corresp">
          <p>Corresponding author: Ibrahim Abunadi (<email xlink:type="simple">iabunadi@psu.edu.sa</email>).</p>
        </fn>
        <fn fn-type="edited-by">
          <p>Academic editor: </p>
        </fn>
      </author-notes>
      <pub-date pub-type="collection">
        <year>2016</year>
      </pub-date>
      <pub-date pub-type="epub">
        <day>01</day>
        <month>04</month>
        <year>2016</year>
      </pub-date>
      <volume>22</volume>
      <issue>4</issue>
      <fpage>537</fpage>
      <lpage>551</lpage>
      <uri content-type="arpha" xlink:href="http://openbiodiv.net/0F7A5F7F-FE73-5146-94D6-00AAF00620B4">0F7A5F7F-FE73-5146-94D6-00AAF00620B4</uri>
      <uri content-type="zenodo_dep_id" xlink:href="https://zenodo.org/record/5505037">5505037</uri>
      <history>
        <date date-type="received">
          <day>30</day>
          <month>10</month>
          <year>2015</year>
        </date>
        <date date-type="accepted">
          <day>30</day>
          <month>03</month>
          <year>2016</year>
        </date>
      </history>
      <permissions>
        <copyright-statement>Ibrahim Abunadi, Mamdouh Alenezi</copyright-statement>
        <license license-type="creative-commons-attribution" xlink:href="" xlink:type="simple">
          <license-p>This article is freely available under the J.UCS Open Content License.</license-p>
        </license>
      </permissions>
      <abstract>
        <label>Abstract</label>
        <p>Building secure software is challenging, time-consuming, and expensive. Software vulnerability prediction models that identify vulnerable software components are usually used to focus security efforts, with the aim of helping to reduce the time and effort needed to secure software. Existing vulnerability prediction models use process or product metrics and machine learning techniques to identify vulnerable software components. Cross-project vulnerability prediction plays a significant role in appraising the most likely vulnerable software components, specifically for new or inactive projects. Little effort has been spent to deliver clear guidelines on how to choose the training data for project vulnerability prediction. In this work, we present an empirical study aiming at clarifying how useful cross-project prediction techniques are in predicting software vulnerabilities. Our study employs the classification provided by different machine learning techniques to improve the detection of vulnerable components. We have elaborately compared the prediction performance of five well-known classifiers. The study is conducted on a publicly available dataset of several PHP open-source web applications in the context of cross-project vulnerability prediction, which represents one of the main challenges in the vulnerability prediction field.</p>
      </abstract>
    </article-meta>
  </front>
</article>
