• DocumentCode
    1122542
  • Title

    Taxonomies of attacks and vulnerabilities in computer systems

  • Author

    Igure, Vinay M. ; Williams, Ronald D.

  • Author_Institution
    Virginia Univ., Charlottesville, VA
  • Volume
    10
  • Issue
    1
  • fYear
    2008
  • Firstpage
    6
  • Lastpage
    19
  • Abstract
    Security assessment of a system is a difficult problem. Most of the current efforts in security assessment involve searching for known vulnerabilities. Finding unknown vulnerabilities still largely remains a subjective process. The process can be improved by understanding the characteristics and nature of known vulnerabilities. The knowledge thus gained can be organized into a suitable taxonomy, which can then be used as a framework for systematically examining new systems for similar but as yet unknown vulnerabilities. There have been many attempts at producing such taxonomies. This article provides a comprehensive survey of the important work done on developing taxonomies of attacks and vulnerabilities in computer systems. This survey covers work done in security related taxonomies from 1974 until 2006. Apart from providing a state-of-the-art survey of taxonomies, we also analyze their effectiveness for use in a security assessment process. Finally, we summarize the important properties of various taxonomies to provide a framework for organizing information about known attacks and vulnerabilities into a taxonomy that would benefit the security assessment process.
  • Keywords
    telecommunication security; computer system attacks; computer system vulnerabilities; information organization; security assessment; taxonomies; Buildings; Communication system security; Data security; Databases; Information security; Organizing; Standards publication; Taxonomy;
  • fLanguage
    English
  • Journal_Title
    Communications Surveys & Tutorials, IEEE
  • Publisher
    ieee
  • ISSN
    1553-877X
  • Type

    jour

  • DOI
    10.1109/COMST.2008.4483667
  • Filename
    4483667