|国家预印本平台
首页|Vulnerability Webs: Systemic Risk in Software Networks

Vulnerability Webs: Systemic Risk in Software Networks

Vulnerability Webs: Systemic Risk in Software Networks

来源:Arxiv_logoArxiv
英文摘要

Software development relies on code reuse to minimize costs, creating vulnerability risks through dependencies with substantial economic impact, as seen in the Crowdstrike and HeartBleed incidents. We analyze 52,897 dependencies across 16,102 Python repositories using a strategic network formation model incorporating observable and unobservable heterogeneity. Through variational approximation of conditional distributions, we demonstrate that dependency creation generates negative externalities. Vulnerability propagation, modeled as a contagion process, shows that popular protection heuristics are ineffective. AI-assisted coding, on the other hand, offers an effective alternative by enabling dependency replacement with in-house code.

Cornelius Fritz、Co-Pierre Georg、Angelo Mele、Michael Schweinberger

信息产业经济计算技术、计算机技术

Cornelius Fritz,Co-Pierre Georg,Angelo Mele,Michael Schweinberger.Vulnerability Webs: Systemic Risk in Software Networks[EB/OL].(2025-07-01)[2025-08-02].https://arxiv.org/abs/2402.13375.点此复制

评论