首页> 外文会议>IEEE Annual Computer Software and Applications Conference >Benchmark Requirements for Assessing Software Security Vulnerability Testing Tools
【24h】

Benchmark Requirements for Assessing Software Security Vulnerability Testing Tools

机译:评估软件安全漏洞测试工具的基准要求

获取原文

摘要

Consistent growth in the software sector of the world economies has attracted both targeted and mass-scale attacks by cybercriminals. Producing reliable and secure software is difficult because of its growing complexity and the increasing number of sophisticated attacks. Developers cannot afford to believe that their security measures during development are perfect and impenetrable. In fact, many new software security vulnerabilities are discovered on a daily basis. Therefore, it is vital to identify and resolve those security vulnerabilities as early as possible. Security Vulnerability Testing (SVT), as an active defense, is the key to the agile detection and prevention of known and unknown security vulnerabilities. However, many software engineers lack the awareness of the importance of security vulnerability and the necessary knowledge and skills at the testing and operational stages. As a first step towards filling this gap, this paper advocates for building skills in selecting proper benchmarks for the assessment of SVT tools to enable distinguishing effective security tools from trivial ones. Thus, we develop a set of benchmark requirements to fulfill this need, primarily guiding newcomers and researcher into this discipline.
机译:世界经济体软件部门的一致增长引起了网络犯罪分子的目标和大规模攻击。由于其增长复杂性和越来越多的复杂攻击,因此难以生产可靠和安全的软件。开发商不能相信其在开发期间的安全措施是完美的和难以承受的。实际上,每天发现许多新的软件安全漏洞。因此,尽早识别和解决这些安全漏洞至关重要。安全漏洞测试(SVT)作为主动防御是敏捷检测和预防知名和未知安全漏洞的关键。然而,许多软件工程师缺乏对安全漏洞的重要性以及测试和运营阶段所必需的知识和技能的认识。作为填补这一差距的第一步,本文提倡在为评估SVT工具选择适当的基准方面的技能,以实现从琐碎的工具区别有效的安全工具。因此,我们开发了一套基准要求,以实现这一需求,主要是指导新人和研究人员进入这一学科。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号