课题基金 / 基金详情

SGER: A Security Scoring Vector for Web Applications

SGER: A Security Scoring Vector for Web Applications
SGER:Web 应用程序的安全评分向量
批准号:
0335720
负责人:
Russell Barton
金额:
$9.9万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-08-15 至 2005-07-31

项目摘要

项目成果

Russell Barton的其他基金

相似基金

相关文献

中文摘要
翻译
现有的安全性评分方法实现起来很昂贵,缺乏管理导向,并且是基于“最佳实践”的,因此只有短暂的意义。本文研究了一种基于安全评分向量(S-vector)的web应用程序安全评估方法的可行性。IT管理员将使用s向量评估方法来管理其web应用程序的安全性。它与绝缘的r值有一些相似的特征。像r值一样,它是为非专家决策者设计的。与r值一样,必须将数值得分与要求进行比较,以判断是否足够(阁楼的保温要求高于车库门的要求)。与r值不同的是,此特征不会由单个数字组成,而是由一系列安全维度上的数字特征组成。拟议的研究将确定基于s向量的方法是否能满足这些要求,如果满足,如何确定适当的元素,如何估计它们的值,如何将性能与需求进行比较,以及如何构建并将结果呈现给管理层。这项研究是与宾夕法尼亚州联邦合作进行的。州和地方政府必须通过将稀缺资源分配给有问题的web应用程序来管理安全性,并在其完整的web应用程序集上展示安全性改进。如果成功,s向量方法将识别出最易受攻击的web应用程序,并指出其弱点的本质。s向量评分将使各国政府能够相互比较,找出哪些有效,哪些无效。此外,国土安全问题需要采取行动:在网络访问和网络应用程序安全之间存在固有的紧张关系。s向量提供了一种呈现安全目标和评估差距的方法。最后,本研究的成果可能为与安全评估相关的高新技术企业提供机会。
英文摘要
Existing Security scoring methods are expensive to implement, lack management orientation, and are "best practice" based, and thus have only transient meaning. This research investigates the feasibility of a web application security assessment method based on a security scoring vector (S-vector). The S-vector assessment method would be used by IT administrators to manage the security of their web applications. It shares some analogous features with the R-value for insulation. Like the R-value, it is designed to be used by non-expert decision makers. Like the R-value, the numerical score must be compared with requirements to judge the adequacy (attic insulation requirements are higher than garage door requirements). Unlike the R-value, this characterization will not consist of a single number, but rather a set of numerical characterizations along a number of security dimensions. The proposed research will determine whether a method based on an S-vector can meet these requirements and, if so, how to identify the appropriate elements, how to estimate their values, how to compare performance against requirements, and how to structure and present the results to management. This research is being conducted in partnership with the Commonwealth of Pennsylvania.State and local governments must manage security by allocating scarce resources to problem web applications, and demonstrate security improvement over their complete set of web applications. If successful, the S-vector approach will identify the most vulnerable web applications and suggest the nature of their weaknesses. S-vector scores will allow governments to benchmark with each other to find what works and what doesn't. In addition, Homeland Security issues will require action: there inherently will be a tension between web access and web application security. An S-vector permits a way to present security targets and assess gaps. Finally, the product of this research may provide opportunities for new high-tech businesses related to security assessment.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SGER: Multiscale Methods for Supply Chain Monitoring
GOALI: Adjustment and Monitoring Methods for Multiple-Stream and Process-Oriented Quality Control
Process-Oriented Basis Representations for Multivariate Process Diagnosis and Control
Metamodel-Based Integration Technology for MultidisciplinaryDesign
海外基金