DocumentCode :
3128924
Title :
Towards Unified Vulnerability Assessment with Open Data
Author :
Nakamura, A.
Author_Institution :
Inf. Technol. Res. Inst., Nat. Inst. of Adv. Ind. Sci. & Technol. (AIST), Tsukuba, Japan
fYear :
2013
fDate :
22-26 July 2013
Firstpage :
248
Lastpage :
253
Abstract :
Continuous and comprehensive vulnerability management is a difficult task for administrators. The difficulties are not because of a lack of tools, but because they are designed without service-oriented architecture viewpoint and there is insufficient trustworthy machine-readable input data. This paper presents a service-oriented architecture for vulnerability assessment systems based on the open security standards and related contents. If the functions are provided as a service, various kinds of security applications can be interoperated and integrated in loosely-coupled way. We also studied the effectiveness of the available public data for automated vulnerability assessment. Despite the large amount of efforts that goes toward describing machine-readable assessment test in conformity to the OVAL standard, the evaluation result proves inadequate for comprehensive vulnerability assessment. Only about 12% of all the known vulnerabilities are covered by existing OVAL tests, while some popular client applications in the Top 30 with most unique vulnerabilities are covered more than 90%.
Keywords :
security of data; service-oriented architecture; OVAL standard; machine-readable assessment test; open security standard; service-oriented architecture; unified vulnerability assessment; vulnerability management; Data models; Databases; Security; Servers; Software; Standards; XML; CVE; OVAL; SCAP; SOA; cloud computing; computer security; vulnerability assessment;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Software and Applications Conference Workshops (COMPSACW), 2013 IEEE 37th Annual
Conference_Location :
Japan
Type :
conf
DOI :
10.1109/COMPSACW.2013.34
Filename :
6605797
Link To Document :
بازگشت