首页> 外文会议>International security protocols workshop >The Evolution of a Security Control or Why Do We Need More Qualitative Research of Software Vulnerabilties? (Transcript of Discussion)
【24h】

The Evolution of a Security Control or Why Do We Need More Qualitative Research of Software Vulnerabilties? (Transcript of Discussion)

机译:安全控制的演变还是我们为什么需要对软件漏洞进行更多的定性研究? (讨论记录)

获取原文

摘要

Hi, my name is Olgierd Pieczul and this is a joint work with Simon Foley. Inspired by the theme of today's workshop we decided to look at evolution of security controls and vulnerabilities. Today, evolution of software vulnerabilities tends to be researched mostly by using various types of quantitative analysis. These studies often take large numbers of software components, or security advisory records, and process them automatically. Based on that they make broad claims about the health of software security, identify trends, and so forth. These results are, however, somewhat expected, if not entirely, obvious findings. Although quantitative analysis provides some insight into general trends of vulnerability evolution, it does not really help to understand how and why software vulnerabilities and protection mechanims evolve. This is due to the fact that the studies are often based on data that is easy to acquire and process, for example, synthetic metrics such as CVSS. They are straightforward to analyze at a large scale and draw conclusions.
机译:嗨,我叫Olgierd Pieczul,这是西蒙·佛利(Simon Foley)的作品。受今天研讨会主题的启发,我们决定研究安全控制和漏洞的演变。如今,软件漏洞的演变趋势往往是通过使用各种类型的定量分析来研究的。这些研究通常会使用大量软件组件或安全建议记录,并自动对其进行处理。基于此,他们对软件安全性的健康提出了广泛的要求,确定了趋势等等。但是,这些结果在某种程度上是可以预期的,即使不是全部,也是显而易见的发现。尽管定量分析可以洞悉漏洞发展的总体趋势,但它并不能真正帮助理解软件漏洞和保护机制的发展方式和原因。这是由于这样的事实,即研究通常基于易于获取和处理的数据,例如CVSS等综合指标。它们很容易进行大规模分析并得出结论。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号