首页> 外文期刊>IEEE Transactions on Reliability >Application of Vulnerability Discovery Models to Major Operating Systems
【24h】

Application of Vulnerability Discovery Models to Major Operating Systems

机译:漏洞发现模型在主要操作系统上的应用

获取原文
获取原文并翻译 | 示例

摘要

A number of security vulnerabilities have been reported in the Windows, and Linux operating systems. Both the developers, and users of operating systems have to utilize significant resources to evaluate, and mitigate the risk posed by these vulnerabilities. Vulnerabilities are discovered throughout the life of a software system by both the developers, and external testers. Vulnerability discovery models are needed that describe the vulnerability discovery process for determining readiness for release, future resource allocation for patch development, and evaluating the risk of vulnerability exploitation. Here, we analytically describe six models that have been recently proposed, and evaluate those using actual data for four major operating systems. The applicability of the proposed models, and the significance of the parameters involved are examined. The results show that some of the models tend to capture the discovery process better than others.
机译:Windows和Linux操作系统中已报告了许多安全漏洞。操作系统的开发人员和用户都必须利用大量资源来评估和减轻这些漏洞带来的风险。开发人员和外部测试人员都会在软件系统的整个生命周期中发现漏洞。需要使用漏洞发现模型来描述漏洞发现过程,以确定发布的准备情况,将来的修补程序资源分配以及评估漏洞利用的风险。在这里,我们分析性地描述了最近提出的六个模型,并使用四个主要操作系统的实际数据对它们进行了评估。所提出的模型的适用性,以及所涉及的参数的重要性进行了检查。结果表明,某些模型倾向于比其他模型更好地捕获发现过程。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号