摘要
引入了特权集、机密性、完整性和可用性等量化属性,设计并实现了一个量化的多属性弱点数据库,同时对弱点数据进行了进一步的分析。实践表明,该弱点数据库能够为安全评估提供更细致、更有力的弱点信息支持。
Authors designed and established a multi-attribute quantitative vulnerability database, by introducing attributes like privilege sets, confidentiality, integrality, availability. The vulnerability information was also analyzed further. Practice has proved that it is a more comprehensive and powerful way for security assessment system by using this vulnerability information support.
出处
《计算机应用研究》
CSCD
北大核心
2007年第3期213-214,217,共3页
Application Research of Computers
基金
国防十五预研项目(41315.7.1)
关键词
弱点数据库
弱点分类法
安全评估
特权提升
vulnerability database
vulnerability taxonomy
security evaluation
privilege escalation