Common vulnerability markup language

被引:0
|
作者
Tian, HT [1 ]
Huang, LS [1 ]
Zhou, Z [1 ]
Zhang, H [1 ]
机构
[1] Univ Sci & Technol China, Dept Comp Sci, Hefei 230026, Anhui, Peoples R China
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Discovering, disclosing, and patching vulnerabilities in computer systems play a key role in the security area, but now vulnerability information from different sources is usually ambiguous text-based description that can't be efficiently shared and used in automated process. After explaining a model of vulnerability life cycle, this paper presents an XML-based common vulnerability markup language (CVML) describing vulnerabilities in a more structural way. Besides regular information contained in most of current vulnerability databases, information about classification, evaluation, checking existence and attack generation is also given in CVML. So it supports automated vulnerability assessment and remedy. A prototype of automated vulnerability management architecture based on CVML has been implemented. More manageable vulnerability databases will be built; promulgating and sharing of vulnerability knowledge will be easier; comparison and fusion of vulnerability information from different sources will be more efficient; moreover automated scanning and patching of vulnerabilities will lead to self-managing systems.
引用
收藏
页码:228 / 240
页数:13
相关论文
共 50 条
  • [1] Towards a common framework for multimodal generation:: The behavior markup language
    Kopp, Stefan
    Krenn, Brigitte
    Marsella, Stacy
    Marshall, Andrew N.
    Pelachaud, Catherine
    Pirker, Hannes
    Thorisson, Kristinn R.
    Vilhjalmsson, Hannes
    INTELLIGENT VIRTUAL AGENTS, PROCEEDINGS, 2006, 4133 : 205 - 217
  • [2] Suffering, language and meaning: a common vulnerability
    Higgins, Robert William
    MEDECINE PALLIATIVE, 2007, 6 (03): : 188 - 194
  • [3] Extensible markup language
    Bray, T
    SperbergMcQueen, CM
    SGML '96 CONFERENCE PROCEEDINGS - CELEBRATING A DECADE OF SGML, 1996, : 399 - 404
  • [4] Extensible markup language
    Udell, J
    BYTE, 1998, 23 (01): : 80 - 80
  • [5] The chemical markup language
    Liao, YM
    Ghanadan, H
    ANALYTICAL CHEMISTRY, 2002, 74 (13) : 389A - 390A
  • [6] CHEMICAL MARKUP LANGUAGE
    MURRAYRUST, P
    LEACH, C
    RZEPA, HS
    ABSTRACTS OF PAPERS OF THE AMERICAN CHEMICAL SOCIETY, 1995, 210 : 40 - COMP
  • [7] The biopolymer markup language
    Fenyö, D
    BIOINFORMATICS, 1999, 15 (04) : 339 - 340
  • [8] Intensional markup language
    Wadge, WW
    DISTRIBUTED COMMUNITIES ON THE WEB, PROCEEDINGS, 2000, 1830 : 82 - 89
  • [9] Incorporating Units Markup Language (UnitsML) into AnIML (Analytical Information Markup Language)
    Jopp, Ronny
    Roth, Alexander
    Linstrom, Peter J.
    Kramer, Gary W.
    ABSTRACTS OF PAPERS OF THE AMERICAN CHEMICAL SOCIETY, 2006, 231
  • [10] Unambiguous syntactic eXtensible Markup Language query matching on eXtensible Markup Language streams
    Chou, Chien-Ping
    Jea, Kuen-Fang
    CONCURRENT ENGINEERING-RESEARCH AND APPLICATIONS, 2014, 22 (01): : 38 - 47