Windows of Vulnerability: A Case Study Analysis

Windows of Vulnerability: A Case Study Analysis
复制标题

DOI:
10.1109/2.889093
复制
发表时间:
2000-12
期刊:
影响因子:
2.2
通讯作者:
W. Arbaugh;William L. Fithen;John McHugh
W. Arbaugh;William L. Fithen;John McHugh
中科院分区:
计算机科学4区
文献类型:
--
作者:
W. Arbaugh;William L. Fithen;John McHugh

文献摘要

被引文献

相似文献

作者提出了一个系统漏洞的生命周期模型,然后将其应用于三个案例研究,以揭示系统如何在安全修复后长期保持脆弱性。对于每种情况,我们都提供了有关漏洞的背景信息,例如攻击者如何利用它以及哪些系统受到影响。然后,我们通过确定模型中每个状态的日期,将案例与生命周期模型联系起来。最后,我们使用报告的入侵直方图来显示漏洞的生命周期,并以特定于特定漏洞的分析作为结论。
The authors propose a life cycle model for system vulnerabilities, then apply it to three case studies to reveal how systems often remain vulnerable long after security fixes are available. For each case, we provide background information about the vulnerability, such as how attackers exploited it and which systems were affected. We then tie the case to the life-cycle model by identifying the dates for each state within the model. Finally, we use a histogram of reported intrusions to show the life of the vulnerability, and we conclude with an analysis specific to the particular vulnerability.