...
首页> 外文期刊>International journal of information and computer security >Vulnerability distribution scoring for software product security assessment
【24h】

Vulnerability distribution scoring for software product security assessment

机译:软件产品安全评估的漏洞分布评分

获取原文
获取原文并翻译 | 示例

摘要

Objective and measurable enterprise security remains elusive despite the increasing importance of IT security in many organisations. Some security assurance tasks within the field are subject to significant theoretical and technical challenges. One area in which progress is more tangible is software security assessment. Despite some shortcomings in the available data, there is still enough information available to begin making more detailed analyses which can improve decision making on enterprise security. The current study presents an approach for software security assessment called Vulnerability Distribution Scoring which evaluates a software product based on the characteristics of the vulnerabilities it has exhibited. Results are presented from applying the approach to the national vulnerability database (NVD) and demonstrate an effective means of rating the security of software products and software vendors.
机译:尽管在许多组织中IT安全性的重要性日益提高,但客观而可衡量的企业安全性仍然难以捉摸。该领域内的某些安全保证任务面临着重大的理论和技术挑战。软件安全评估是其中更明显的进步之一。尽管可用数据存在一些缺陷,但是仍然有足够的信息可用于开始进行更详细的分析,从而可以改善企业安全性的决策。当前的研究提出了一种称为“漏洞分布评分”的软件安全评估方法,该方法根据所表现出的漏洞的特征来评估软件产品。通过将该方法应用于国家漏洞数据库(NVD),可以得出结果,并证明了对软件产品和软件供应商的安全性进行评级的有效手段。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号