课题基金 / 基金详情

SGER: A Security Scoring Vector for Web Applications

SGER: A Security Scoring Vector for Web Applications
SGER:Web 应用程序的安全评分向量
批准号:
0335720
负责人:
Russell Barton
金额:
$9.9万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-08-15 至 2005-07-31

项目摘要

项目成果

Russell Barton的其他基金

相似基金

相关文献

中文摘要
翻译
现有的安全评分方法实施起来很昂贵,缺乏管理导向,并且是基于“最佳实践”的,因此只有短暂的意义。研究了一种基于安全评分向量(S-vector)的Web应用安全评估方法的可行性。IT管理员将使用S向量评估方法来管理其Web应用程序的安全性。它与绝缘的R值有一些类似的特征。与R值一样,它也是为非专家决策者设计的。与R值一样,数值分数必须与要求进行比较,以判断是否充分(阁楼隔热要求高于车库门要求)。与R值不同,该特征将不包括单个数字,而是沿着沿着多个安全维度的一组数字特征。拟议的研究将确定基于S-向量的方法是否能够满足这些要求,如果能够,如何确定适当的要素,如何估计它们的值,如何将性能与要求进行比较,以及如何将结果结构化并提交给管理层。这项研究是与宾夕法尼亚州联邦合作进行的。州和地方政府必须通过将稀缺资源分配给有问题的Web应用程序来管理安全性,并证明其完整的Web应用程序的安全性改进。如果成功,S-vector方法将识别最脆弱的Web应用程序,并提出其弱点的性质。S-vector分数将允许政府相互进行基准测试,以找出哪些有效,哪些无效。此外,国土安全问题将需要采取行动:Web访问和Web应用程序安全之间必然存在紧张关系。S向量允许一种方式来呈现安全目标和评估差距。最后,本研究的成果可提供与安全评估相关的新兴高科技产业发展机会。
英文摘要
Existing Security scoring methods are expensive to implement, lack management orientation, and are "best practice" based, and thus have only transient meaning. This research investigates the feasibility of a web application security assessment method based on a security scoring vector (S-vector). The S-vector assessment method would be used by IT administrators to manage the security of their web applications. It shares some analogous features with the R-value for insulation. Like the R-value, it is designed to be used by non-expert decision makers. Like the R-value, the numerical score must be compared with requirements to judge the adequacy (attic insulation requirements are higher than garage door requirements). Unlike the R-value, this characterization will not consist of a single number, but rather a set of numerical characterizations along a number of security dimensions. The proposed research will determine whether a method based on an S-vector can meet these requirements and, if so, how to identify the appropriate elements, how to estimate their values, how to compare performance against requirements, and how to structure and present the results to management. This research is being conducted in partnership with the Commonwealth of Pennsylvania.State and local governments must manage security by allocating scarce resources to problem web applications, and demonstrate security improvement over their complete set of web applications. If successful, the S-vector approach will identify the most vulnerable web applications and suggest the nature of their weaknesses. S-vector scores will allow governments to benchmark with each other to find what works and what doesn't. In addition, Homeland Security issues will require action: there inherently will be a tension between web access and web application security. An S-vector permits a way to present security targets and assess gaps. Finally, the product of this research may provide opportunities for new high-tech businesses related to security assessment.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SGER: Multiscale Methods for Supply Chain Monitoring
GOALI: Adjustment and Monitoring Methods for Multiple-Stream and Process-Oriented Quality Control
Process-Oriented Basis Representations for Multivariate Process Diagnosis and Control
Metamodel-Based Integration Technology for MultidisciplinaryDesign
海外基金