
software developers in Source-Forge.net was realized 
by Xu et al (Xu, 2006) then by Surian et al (Surian, 
2010) in order to study the interaction and the 
influence between software developer and code 
source evolution. From this study appeared the notion 
of experts in specific technologies. Other studies like 
(Xu, 2006) and (Tian Y. 2012) focused on analysing 
software engineering trends on Twitter. The notion of 
software popularity appeared in these studies. 
Bug tracking monitoring on social media was also 
addressed in (Sureka, 2011) for open source public 
trackers and in (Jiang, 2013) for mobile OS Android 
bug reporting community. These studies focus on the 
bug reporting lines and management. They identify 
the strategies and the authority organization structure 
for handling bugs during the software development 
phase. 
6  CONCLUSIONS 
In this paper, we explore a new information source, 
namely Social Media streams, to aggregate 
information about new software vulnerabilities. This 
channel offers the possibility to track announcements 
coming from software vendors, NVD but also other 
non-structured sources publishing 0-day 
vulnerabilities, CVE requests, exploits etc. We 
obtained some interesting results especially about the 
impressive number of 0-day vulnerabilities related to 
the Linux-Kernel software published before the 
official NVD announcements. We claim that SM 
analysis can offer a cheap and easy way to efficiently 
monitor system security. It also offers many other 
possibilities to handle and monitor patching and 
security maintenance for complex systems that we are 
currently under exploration as future work. The 
current version of the tool relies on many manual 
tasks, especially for the validation of the detected 
information; the goal in the short term is to automate 
these tasks. We are also working on the validation of 
the trust model about the validity of the score 
estimation.  
REFERENCES 
Jiang, Feng, Jiemin Wang, Abram Hindle, and Mario A. 
Nascimento., 2013. "Mining the Temporal Evolution of 
the Android Bug Reporting Community via Sliding 
Windows." arXiv preprint arXiv:1310.7469. 
Bougie, G., Starke, J., Storey, M. A., & German, D. M., 
2011.  Towards understanding twitter use in software 
engineering: preliminary findings, ongoing challenges 
and future questions. In Proceedings of the 2nd 
international workshop on Web 2.0 for software engi-
neering (pp. 31-36). ACM. 
Tian, Y., Achananuparp, P., Lubis, I. N., Lo, D., & Lim, E. 
P., 2012. What does software engineering community 
microblog about? In Mining Software Repositories 
(MSR), 9th IEEE Working Conference on (pp. 247-
250). IEEE. 
J. B. MacQueen, 1967. “Some methods for classification 
and analysis of multivariate observa-tions,” in Proc. of 
the fifth Berkeley Symposium on Mathematical 
Statistics and Probability (L. M. L. Cam and J. Neyman, 
eds.), vol. 1, pp. 281–297, University of California 
Press. 
Rajput, D. S., Thakur, R. S., Thakur, G. S., & Sahu, N. 
2012.  “Analysis of Social net-working sites using K-
mean Clustering algorithm”. International Journal of 
Computer & Communication Technology (IJCCT) 
ISSN (ONLINE), 2231-0371. 
C. Bird, A. Gourley, P. T. Devanbu, M. Gertz, and A. 
Swaminathan, 2006 “Mining email social networks,” 
in MSR, pp. 137–143. 
D. Surian, D. Lo, and E.-P. Lim, 2010 “Mining 
collaboration patterns from a large developer net-
work,” in WCRE, pp. 269–273. 
Xu, Jin, Scott Christley, and Greg Madey. 2006 
"Application of social network analysis to the study of 
open source software." The economics of open source 
software development: 205-224. 
Bougie, Gargi, Jamie Starke, Margaret-Anne Storey, and 
Daniel M. German. 2011 "Towards un-derstanding 
twitter use in software engineering: preliminary 
findings, ongoing challenges and future questions." In 
Proceedings of the 2nd international workshop on Web 
2.0 for software engineering, pp. 31-36. ACM. 
Tian, Yuan, Palakorn Achananuparp, Ibrahim Nelman 
Lubis, David Lo, and Ee-Peng Lim. 2012 "What does 
software engineering community microblog about?" In 
Mining Software Re-positories (MSR), 2012 9th IEEE 
Working Conference on, pp. 247-250. IEEE. 
Sureka, Ashish, Atul Goyal, and Ayushi Rastogi. 2011 
"Using social network analysis for mining 
collaboration data in a defect tracking system for risk 
and vulnerability analysis." In Proceed-ings of the 4th 
India Software Engineering Conference, pp. 195-204. 
ACM. 
Arafin, Md Tanvir, and Richard Royster. 2013 
"Vulnerability Exploits Advertised on Twitter.". 
Cui, B., Moskal, S., Du, H., & Yang, S. J. (2013). Who shall 
we follow in twitter for cyber vulnerability?. In Social 
Computing, Behavioral-Cultural Modeling and 
Prediction (pp. 394-402). Springer Berlin Heidelberg. 
Turney, Peter D., and Patrick Pantel. "From frequency to 
meaning: Vector space models of semantics." Journal 
of artificial intelligence research 37.1 (2010): 141-188. 
 
 
 
SECRYPT2015-InternationalConferenceonSecurityandCryptography
242