计算机应用 ›› 2010, Vol. 30 ›› Issue (8): 2139-2142.

• 信息安全 • 上一篇    下一篇

基于属性综合评价系统的漏洞静态严重性评估

肖云1,彭进业1,王选宏2   

  1. 1. 西北大学
    2. 西安邮电学院
  • 收稿日期:2010-02-03 修回日期:2010-03-20 发布日期:2010-07-30 出版日期:2010-08-01
  • 通讯作者: 肖云
  • 基金资助:
    国防基础科研项目;陕西省教育厅自然科学专项

Evaluation of vulnerability static severity based on attribute synthetic assessment system

  • Received:2010-02-03 Revised:2010-03-20 Online:2010-07-30 Published:2010-08-01

摘要: 针对计算机安全漏洞的静态严重性评估问题,提出了一种基于属性综合评价系统的漏洞静态严重性分析方法。该方法从漏洞的基本属性中提取漏洞的威胁性、影响度、流行性和修补难易4个指标,运用属性综合评价系统理论评价其静态严重性,获得二元组表示的漏洞静态严重性,其中的定性表示值表示漏洞的静态严重性等级,定量表示值表示漏洞静态严重性分值。应用实例表明该方法对于漏洞静态严重性的评估是准确有效的。相比于现有的漏洞严重性分析方法,该方法兼备了定性和定量表示的优点,体现了同一级别之下不同漏洞的静态严重性的细微差别

关键词: 漏洞, 属性综合评判系统, 静态严重性

Abstract: To solve the problem of evaluating static severity of computer security vulnerability, a method of evaluating vulnerability static severity based on the attribute synthetic assessment system was proposed. Four factors: threat, epidemic, incidence and easy or hard repair were advanced from the basic attributes of vulnerability, and the proposed method used the attribute synthetic assessment system to get a binary tuple denotation of vulnerability static severity of which qualitative denotation shows static severity rank and quantitative denotation shows static severity metirc. Application cases show that the proposed method is exact and effective. Compared with other existing methods, the proposed method has merits of quantitative and qualitative denotation, and embodies nuance of different vulnerabilities which are in the same quantitative static severity level.

Key words: vulnerability, attribute synthetic assessment system, static severity