首页> 外文会议>Software Security and Reliability (SERE), 2012 IEEE Sixth International Conference on >VRank: A Context-Aware Approach to Vulnerability Scoring and Ranking in SOA
【24h】

VRank: A Context-Aware Approach to Vulnerability Scoring and Ranking in SOA

机译:VRank:一种基于上下文的SOA漏洞评分和排名方法

获取原文
获取原文并翻译 | 示例

摘要

With the rapid adoption of the concepts of Service Oriented Architecture (SOA), sophisticated business processes and tasks are increasingly realized through composing distributed software components offered by different providers. Though such practices offer advantages in terms of cost-effectiveness and flexibility, those components are not immune to vulnerabilities. It is therefore important for the administrator of some composed service to evaluate the threats of such vulnerabilities accordingly within limited available information. Since almost all the existing efforts (e.g., CVSS) fail to consider specific context-aware information which is the specific character of SOA, they could not be adopted into SOA for scoring vulnerabilities. In this paper, we present VRank, a novel framework for the scoring and ranking of vulnerabilities in SOA. Different from existing efforts, for a given vulnerability, VRank not only considers its intrinsic properties (e.g., exploitability), but also takes into account the contexts of the services having this vulnerability, e.g., what roles they play in the composed service and how critical it is to the security objective of the service. The resulting scoring and ranking of vulnerabilities are thus highly relevant and meaningful to the composed service. We present the detailed design of VRank, and compare it with CVSS. Our experiments indicate VRank is able to provide much more useful ranking lists of vulnerabilities for complex composed services.
机译:随着面向服务体系结构(SOA)概念的迅速采用,通过组合不同提供商提供的分布式软件组件,越来越多地实现了复杂的业务流程和任务。尽管这样的做法在成本效益和灵活性方面都具有优势,但是这些组件并不能不受漏洞的影响。因此,对于某些组合服务的管理员来说,重要的是要在有限的可用信息内评估此类漏洞的威胁。由于几乎所有现有的工作(例如CVSS)都没有考虑到特定的上下文感知信息(这是SOA的特定特征),因此无法将它们用于SOA评分漏洞。在本文中,我们介绍了VRank,这是一个用于对SOA中的漏洞进行评分和排名的新颖框架。与现有的工作不同,对于给定的漏洞,VRank不仅考虑其固有属性(例如,可利用性),而且还考虑具有此漏洞的服务的上下文,例如,它们在组合服务中扮演的角色以及关键程度这是服务的安全目标。因此,所得的漏洞评分和排名与组合服务高度相关且有意义。我们介绍VRank的详细设计,并将其与CVSS进行比较。我们的实验表明,VRank能够为复杂的组合服务提供更有用的漏洞排名列表。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号