DocumentCode
1547387
Title
Managing vulnerabilities in networked systems
Author
Martin, Robert A.
Volume
34
Issue
11
fYear
2001
fDate
11/1/2001 12:00:00 AM
Firstpage
32
Lastpage
38
Abstract
Most organizations recognize the importance of cyber security and are implementing various forms of protection. However, many are failing to find and fix known security problems in the software packages they use as the building blocks of their networks and systems, a vulnerability that a hacker can exploit to bypass all other efforts to secure the enterprise. The Common Vulnerabilities and Exposures (CVE) initiative seeks to avoid such disasters and transform this area from a liability to a key asset in the fight to build and maintain secure systems. Coordinating international, community-based efforts from industry, government and academia, CVE strives to find and fix software product vulnerabilities more rapidly, predictably, and efficiently. The initiative seeks the adoption of a common naming practice for describing software vulnerabilities. Once adopted, these names will be included within security tools and services and on the fix sites of commercial and open source software package providers. As vendors respond to more users requests for CVE-compatible fix sites, securing the enterprise will gradually include the complete cycle of finding, analyzing, and fixing vulnerabilities
Keywords
Internet; security; Common Vulnerabilities and Exposures initiative; common naming practice; cyber security; networked systems; open source software package providers; security problems; security tools; software packages; software product vulnerabilities; Computer errors; Computer hacking; Cryptography; Data security; Information security; Intelligent networks; Open source software; Protection; Software packages; Web server;
fLanguage
English
Journal_Title
Computer
Publisher
ieee
ISSN
0018-9162
Type
jour
DOI
10.1109/2.963441
Filename
963441
Link To Document