首页> 外文会议>Engineering secure software and systems >Report: Measuring the Attack Surfaces of Enterprise Software
【24h】

Report: Measuring the Attack Surfaces of Enterprise Software

机译:报告:测量企业软件的攻击面

获取原文
获取原文并翻译 | 示例

摘要

Software vendors are increasingly concerned about mitigating the security risk of their software. Code quality improvement is a traditional approach to mitigate security risk; measuring and reducing the attack surface of software is a complementary approach. In this paper, we apply a method for measuring attack surfaces to enterprise software written in Java. We implement a tool as an Eclipse plugin to measure an SAP software system's attack surface in an automated manner. We demonstrate the feasibility of our approach by measuring the attack surfaces of three versions of an SAP software system. We envision our measurement method and tool to be useful to software developers for improving software security and quality.
机译:软件供应商越来越关注减轻其软件的安全风险。提高代码质量是减轻安全风险的传统方法。测量和减少软件的攻击面是一种补充方法。在本文中,我们将一种用于测量攻击面的方法应用于用Java编写的企业软件。我们将工具实现为Eclipse插件,以自动方式测量SAP软件系统的攻击面。我们通过测量三个版本的SAP软件系统的攻击面来证明我们的方法的可行性。我们设想我们的测量方法和工具将对软件开发人员有用,以改善软件的安全性和质量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号