论文标题

一套用于计算最重要安全相关软件漏斗类型的指标

A Suite of Metrics for Calculating the Most Significant Security Relevant Software Flaw Types

论文作者

Mell, Peter, Gueye, Assane

论文摘要

常见的弱点枚举(CWE)是软件弱点类型的突出列表。漏洞数据库使用此列表来描述分析漏洞中的基本安全缺陷。这种联系开辟了使用软件漏洞分析来确定能够使这些漏洞的最重要的弱点的可能性。我们通过创建混合视图将CWE弱点分类法与漏洞分析数据结合在一起来实现这一目标。由此产生的图具有CWE作为节点,来自多个CWE分类法的边缘,以及带有脆弱性分析信息(从子女到父母传播)的节点。使用这些图,我们开发了一套指标来识别最重要的弱点类型(使用频率,影响,可剥削性和整体严重性的观点)。

The Common Weakness Enumeration (CWE) is a prominent list of software weakness types. This list is used by vulnerability databases to describe the underlying security flaws within analyzed vulnerabilities. This linkage opens the possibility of using the analysis of software vulnerabilities to identify the most significant weaknesses that enable those vulnerabilities. We accomplish this through creating mashup views combining CWE weakness taxonomies with vulnerability analysis data. The resulting graphs have CWEs as nodes, edges derived from multiple CWE taxonomies, and nodes adorned with vulnerability analysis information (propagated from children to parents). Using these graphs, we develop a suite of metrics to identify the most significant weakness types (using the perspectives of frequency, impact, exploitability, and overall severity).

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源