首页 | 本学科首页   官方微博 | 高级检索  
     


Standardising vulnerability categories
Authors:H.S. Venter   J.H.P. Eloff  Y.L. Li  
Affiliation:aInformation and Computer Security Architectures (ICSA) Research Group, Department of Computer Science, University of Pretoria, Lynnwood Road, Pretoria, Gauteng 0002, South Africa
Abstract:Each vulnerability scanner (VS) represents, identifies and classifies vulnerabilities in its own way, thus making the different scanners difficult to study and compare. Despite numerous efforts by researchers and organisations to solve the disparity in vulnerability names used in the different VSs, vulnerability categories have still not been standardised. This paper highlights the importance of having a standard vulnerability category set. It also outlines an approach towards achieving this goal by generating a standard set of vulnerability categories. A data-clustering algorithm that employs artificial intelligence is used for this purpose. The significance of this research results from having an intelligent technique that aids in the generation of standardised vulnerability categories in a relatively fast way. In addition, the technique is generic in the sense that it allows one to accommodate any VS currently known on the market to create such vulnerability categories. Another benefit is that the approach followed in this paper allows one to also compare various VSs currently available on the market. A prototype is presented to verify the concept.
Keywords:Vulnerability   Vulnerability scanners (VSs)   Common vulnerabilities and exposures (CVE) list   Data clustering   Self-organising map (SOM)   Artificial intelligence
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号