• skip to content
  • skip to navigation
  • skip to supporting content
Homepage
CLOK - Central Lancashire Online Knowledge
Menu
  • Home
  • About
  • Policies
  • Deposit Guide: Research eTheses
  • Copyright Guide
  • Contact
  • Links
    • Login
  • Deposit
  • Search Item
  • Search FullText
  • Browse

Analysis of the NIST database towards the composition of vulnerabilities in attack scenarios

Tools
- Tools
+ Tools

Franqueira, Virginia N.L. and van Keulen, Maurice (2008) Analysis of the NIST database towards the composition of vulnerabilities in attack scenarios. Project Report. Centre for Telematics and Information Technology, University of Twente, Enschede.

[img]
Preview
PDF - Published Version
782Kb

Abstract

The composition of vulnerabilities in attack scenarios has been traditionally performed based on detailed pre- and post-conditions. Although very precise, this approach is dependent on human analysis, is time consuming, and not at all scalable. We investigate the NIST National Vulnerability Database (NVD) with three goals: (i) understand the associations among vulnerability attributes related to impact, exploitability, privilege, type of vulnerability and clues derived from plaintext descriptions, (ii) validate our initial composition model which is based on required access and resulting effect, and (iii) investigate the maturity of XML database technology for performing statistical analyses like this directly on the XML data. In this report, we analyse 27,273 vulnerability entries (CVE 1) from the NVD. Using only nominal information, we are able to e.g. identify clusters in the class of vulnerabilities with no privilege which represent 52% of the entries.


Item Type:Monograph (Project Report)
Subjects:Q Science > Q Science (General)
Q Science > QA Mathematics > QA75 Electronic computers. Computer science
Schools:School of Computing Engineering & Physcial Sciences
ID Code:6089
Deposited By: Carmit Erez
Deposited On:01 Nov 2012 16:36
Last Modified:01 Nov 2012 16:36

Repository Staff Only: item control page

University of Central Lancashire

Preston,
Lancashire,
PR1 2HE

Tel: +44 (0)1772 201 201

Other Links

  • Contact UCLan
  • How to find us
  • Help

  • Facebook
  • Twitter
  • UCLan RSS
  • Contact UCLan
  • Copyright |
  • Disclaimer |
  • Data Protection Act |
  • Freedom of Information