Skip to main content
U.S. flag

An official website of the United States government

Dot gov

The .gov means it’s official.
Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you’re on a federal government site.


The site is secure.
The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.

The Bugs Framework (BF): A Structured Approach to Express Bugs



Irena V. Bojanova, Paul E. Black, Yaacov Yesha, Yan Wu


To achieve higher levels of assurance for digital systems, we need to answer questions such as, does this software have bugs of these critical classes? Do these two tools generally find the same set of bugs, or different, complimentary sets? Can we guarantee that a new technique discovers all problems of this type? To answer such questions, we need a vastly improved way to describe classes of vulnerabilities and chains of failures. This paper presents a descriptive framework that will lift the current realm of best efforts and useful heuristics. Our framework includes rigorous definitions and (static) characteristics of bug classes, along with their related dynamic properties, such as proximate, secondary, and tertiary causes and consequences (CCC), and sites. The paper discusses the buffer overflow class, the injection class, and the interaction frequency control class, and provides examples of applying our taxonomy to describe particular vulnerabilities.
Conference Dates
August 1-3, 2016
Conference Location
Viena, -1
Conference Title
IEEE International Conference on Software Quality, Reliability & Security (QRS 2016)


software weaknesses, bug taxonomy, software vulnerabilities, attacks
Created August 1, 2016, Updated April 26, 2019