DocumentCode
1122542
Title
Taxonomies of attacks and vulnerabilities in computer systems
Author
Igure, Vinay M. ; Williams, Ronald D.
Author_Institution
Virginia Univ., Charlottesville, VA
Volume
10
Issue
1
fYear
2008
Firstpage
6
Lastpage
19
Abstract
Security assessment of a system is a difficult problem. Most of the current efforts in security assessment involve searching for known vulnerabilities. Finding unknown vulnerabilities still largely remains a subjective process. The process can be improved by understanding the characteristics and nature of known vulnerabilities. The knowledge thus gained can be organized into a suitable taxonomy, which can then be used as a framework for systematically examining new systems for similar but as yet unknown vulnerabilities. There have been many attempts at producing such taxonomies. This article provides a comprehensive survey of the important work done on developing taxonomies of attacks and vulnerabilities in computer systems. This survey covers work done in security related taxonomies from 1974 until 2006. Apart from providing a state-of-the-art survey of taxonomies, we also analyze their effectiveness for use in a security assessment process. Finally, we summarize the important properties of various taxonomies to provide a framework for organizing information about known attacks and vulnerabilities into a taxonomy that would benefit the security assessment process.
Keywords
telecommunication security; computer system attacks; computer system vulnerabilities; information organization; security assessment; taxonomies; Buildings; Communication system security; Data security; Databases; Information security; Organizing; Standards publication; Taxonomy;
fLanguage
English
Journal_Title
Communications Surveys & Tutorials, IEEE
Publisher
ieee
ISSN
1553-877X
Type
jour
DOI
10.1109/COMST.2008.4483667
Filename
4483667
Link To Document