Research Article

A Quantitative Assessment Approach to COTS Component Security

Table 4

The comparison with related assessment approaches.

Assessment approachAssessment objectAssessment aspect Is the internal factor considered?Qualitative or quantitative?Is there supporting tool?

Khan and Han [8]Software componentSecurityNoQuantitativeNo
Alhazmi and Malaiya [11]Operating systemVulnerabilityYesQuantitativeNo
Zhang et al. [12]Software systemRisk NoQuantitative; qualitativeNo
Goševa-Popstojanova and Trivedi [15]Software systemReliabilityNoQuantitativeNo
Mkpong-Ruffin [3]Software Risk NoQuantitativeYes
CVSS [16]Software componentVulnerabilityNoQuantitativeYes
QACSCOTS componentSecurityYesQuantitativeYes