首页> 外文会议>Annual Southeast Regional Conference >Security metrics for software systems
【24h】

Security metrics for software systems

机译:软件系统的安全指标

获取原文

摘要

Security metrics for software products provide quantitative measurement for the degree of trustworthiness for software systems. This paper proposes a new approach to define software security metrics based on vulnerabilities included in the software systems and their impacts on software quality. We use the Common Vulnerabilities and Exposures (CVE), an industry standard for vulnerability and exposure names, and the Common Vulnerability Scoring System (CVSS), a vulnerability scoring system designed to provide an open and standardized method for rating software vulnerabilities, in our metric definition and calculation. Examples are provided in the paper, which show that our definition of security metrics is consistent with the common practice and real-world experience about software quality in trustworthiness.
机译:软件产品的安全指标为软件系统的可靠性提供了定量测量。本文提出了一种基于软件系统中包含的漏洞的软件安全度量的新方法及其对软件质量的影响。我们使用常见的漏洞和曝光(CVE),漏洞和曝光名称的行业标准,以及普通漏洞评分系统(CVSS),旨在为我们的指标提供开放式和标准化的方法,以提供开放和标准化的方法,在我们的公制中提供开放和标准化的方法定义和计算。本文提供了示例,表明我们对安全指标的定义与符合值得信赖性的常见实践和现实世界经验一致。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号