Benchmarking the Security of Web Serving Systems Based on Known Vulnerabilities

Benchmarking the Security of Web Serving Systems Based on Known Vulnerabilities
复制标题

基于已知漏洞的 Web 服务系统安全性基准测试

DOI:
--
复制
发表时间:
2011
期刊:
Latin-American Symposium on Dependable Computing
影响因子:
--
通讯作者:
H. Madeira
H. Madeira
中科院分区:
--
文献类型:
--
作者:
N. Mendes;J. Durães;H. Madeira

文献摘要

被引文献

相似文献

本文提出了一种评估使用软件组件或系统时出现的安全风险的方法和工具。根据软件组件上存在的已知漏洞来估计风险。一个自动化工具用于提取和汇总用户报告并可在公共数据库(如OSVDB和NVD)上获得的有关漏洞的信息。该工具生成包括漏洞类型频率、严重性、可利用性、影响等在内的全面报告,并提取影响和代表性等方面之间的关联,从而能够识别给定漏洞的典型影响和最严重影响等方面。拟议的方法在应用于同一类别的系统时,使买家和系统集成商能够确定哪个系统或组件的安全风险较低,从而帮助他们选择使用哪个系统。本文包括一个案例研究,以证明该方法和工具的有效性。
This paper proposes a methodology and a tool to evaluate the security risk presented when using software components or systems. The risk is estimated based on known vulnerabilities existing on the software components. An automated tool is used to extract and aggregate information on vulnerabilities reported by users and available on public databases (e.g., OSVDB and NVD). This tool generates comprehensive reports including the vulnerability type frequency, severity, exploitability, impact, and so on, and extracts correlations between aspects such as impact and representativeness, making possible the identification of aspects such as typical and worst impact for a given vulnerability. The proposed methodology, when applied to systems within the same class, enables buyers and system integrators to identify which system or component presents the lower security risk, helping them to select which system to use. The paper includes a case study to demonstrate the usefulness of the methodology and the tool.