Common vulnerability markup language

被引:0
|
作者
Tian, HT [1 ]
Huang, LS [1 ]
Zhou, Z [1 ]
Zhang, H [1 ]
机构
[1] Univ Sci & Technol China, Dept Comp Sci, Hefei 230026, Anhui, Peoples R China
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Discovering, disclosing, and patching vulnerabilities in computer systems play a key role in the security area, but now vulnerability information from different sources is usually ambiguous text-based description that can't be efficiently shared and used in automated process. After explaining a model of vulnerability life cycle, this paper presents an XML-based common vulnerability markup language (CVML) describing vulnerabilities in a more structural way. Besides regular information contained in most of current vulnerability databases, information about classification, evaluation, checking existence and attack generation is also given in CVML. So it supports automated vulnerability assessment and remedy. A prototype of automated vulnerability management architecture based on CVML has been implemented. More manageable vulnerability databases will be built; promulgating and sharing of vulnerability knowledge will be easier; comparison and fusion of vulnerability information from different sources will be more efficient; moreover automated scanning and patching of vulnerabilities will lead to self-managing systems.
引用
收藏
页码:228 / 240
页数:13
相关论文
共 50 条
  • [31] Multimedia Mashup Markup Language
    Cheok, Lai-Tee
    Rhyu, Sungryeul
    Song, Jaeyeon
    2012 FOURTH INTERNATIONAL CONFERENCE ON MULTIMEDIA INFORMATION NETWORKING AND SECURITY (MINES 2012), 2012, : 298 - 301
  • [32] HTML – Hypertext Markup Language
    Axel C. Schwickert
    Informatik-Spektrum, 1997, 20 (3) : 168 - 169
  • [33] The DARPA Agent Markup Language
    Hendler, J
    McGuinness, DL
    IEEE INTELLIGENT SYSTEMS & THEIR APPLICATIONS, 2000, 15 (06): : 72 - 73
  • [34] The geometry description markup language
    Chytracek, R
    PROCEEDINGS OF CHEP 2001, 2001, : 473 - 476
  • [35] The Typographic Markup Language (TML)
    von Harlessem, Marcus
    Klahold, Andre
    PROCEEDINGS OF THE IASTED EUROPEAN CONFERENCE ON INTERNET AND MULTIMEDIA SYSTEMS AND APPLICATIONS, 2007, : 290 - +
  • [36] 'Hyped' text markup language. XML and the future of web markup
    Warwick, C
    Pritchard, E
    ASLIB PROCEEDINGS, 2000, 52 (05): : 174 - 184
  • [37] Experiment markup langauge: A combined markup language and ontology to represent science
    Chalk, Stuart
    ABSTRACTS OF PAPERS OF THE AMERICAN CHEMICAL SOCIETY, 2014, 247
  • [38] Traffic Camera Markup Language (TCML)
    Cai, Yang
    Bunn, Andrew
    Snyder, Kerry
    VISUAL INFORMATION PROCESSING AND COMMUNICATION III, 2012, 8305
  • [39] SSML: a speech synthesis markup language
    Univ of Edinburgh, Edinburgh, United Kingdom
    Speech Commun, 1-2 (123-133):
  • [40] A dependency markup language for web services
    Tolksdorf, R
    WEB, WEB-SERVICES, AND DATABASE SYSTEMS, 2003, 2593 : 129 - 140