The Development of a Common Vulnerability Enumeration

نویسندگان

  • David W. Baker
  • Steven M. Christey
  • William H. Hill
  • David E. Mann
چکیده

This paper traces the development of a Common Enumeration of Vulnerabilities and Exposures (CVE) that standardizes and lists vulnerabilities and security exposures to facilitate data sharing and comparison across computer vulnerability databases, such as those produced by security tools and academic research. The MITRE Corporation is building a syste m that can integrate and manage vulnerability information from different sources (e.g., network assessment tools, intrusion detection systems [IDSs], archives) in a database for supporting enterprise security operations. However, every information security tool considered for integration has its own vulnerability database. Also, the lack of common naming conventions and a common enumeration of the vulnerabilities in the vulnerability databases hindered integration efforts. Thus, MITRE developed CVE to provide a common vocabulary for its vulnerability database system effort. CVE provides a mechanism for information security community discussion on vulnerability identification and other related security issues. CVE development was broadened by creating a CVE Editorial Board, which includes information security community representatives from tool vendors, research and educational organizations, MITRE, and others. The CVE Editorial Board is currently enumerating a large number of vulnerabilities, while simultaneously attempting to capture and codify the decision-making process. When a significant number of vulnerabilities are validated and verified, an initial version of CVE will be released to the public. The document includes background information on MITRE's early CVE activities, a draft CVE design, CVE content and use, and lessons learned.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Security Metrics for Software System

Security metrics for software systems provide quantitative measurement for the degree of trustworthiness for software systems. This paper proposes a new approach to define software security metrics based on vulnerabilities included in the software systems and their impacts on software quality. We use the Common Vulnerabilities and Exposures (CVE), an industry standard for vulnerability and expo...

متن کامل

Zoning of Ecological Vulnerability of Kerman Province to Achieve Sustainable Industrial Development Using AHP Technigue

Introduction: Vulnerability of people and places is a complex phenomenon has been created as a result of human and environment interaction during the ages. The concept of vulnerability addresses the probability of being destructed or damaged of a society, structure, service or a geographical area due to a specific danger. Nowadays there is frequent demand for settling industrial infrastructures...

متن کامل

Semi-Automatic Annotation of Natural Language Vulnerability Reports

Those who do not learn from past vulnerabilities are bound to repeat it. Consequently, there have been several research efforts to enumerate and categorize software weaknesses that lead to vulnerabilities. The Common Weakness Enumeration (CWE) is a community developed dictionary of software weakness types and their relationships, designed to consolidate these efforts. Yet, aggregating and class...

متن کامل

ASVC: An Automatic Security Vulnerability Categorization Framework Based on Novel Features of Vulnerability Data

— Security vulnerabilities are a main cause of network security. Vulnerability classification gives us a better understanding of the essence of vulnerabilities, which help propose efficient solutions. However, applying Vulnerability Categorization Standard (VCS) to manually categorize vulnerabilities is impracticable since it is time-consuming and subjective. To address this issue, a new frame...

متن کامل

Suitability of MRS-bile Agar for the Selective Enumeration of Mixed Probiotic Bacteria in Presence of Mesophilic Lactic Acid Cultures and Yoghurt Bacteria

Measuring the viability of probiotic microorganisms in food products using plate count methodology is a common practice due to the simplicity (ease of performance), inexpensive and routine testing characters ofthis method. In present study, the suitability of de man rogosa and sharpe agar (MRS) bile agar medium forthe selective enumeration of mixed probiotic bacteria (Lactobacillus ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 1999