Common vulnerability markup language

被引:0
|
作者
Tian, HT [1 ]
Huang, LS [1 ]
Zhou, Z [1 ]
Zhang, H [1 ]
机构
[1] Univ Sci & Technol China, Dept Comp Sci, Hefei 230026, Anhui, Peoples R China
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Discovering, disclosing, and patching vulnerabilities in computer systems play a key role in the security area, but now vulnerability information from different sources is usually ambiguous text-based description that can't be efficiently shared and used in automated process. After explaining a model of vulnerability life cycle, this paper presents an XML-based common vulnerability markup language (CVML) describing vulnerabilities in a more structural way. Besides regular information contained in most of current vulnerability databases, information about classification, evaluation, checking existence and attack generation is also given in CVML. So it supports automated vulnerability assessment and remedy. A prototype of automated vulnerability management architecture based on CVML has been implemented. More manageable vulnerability databases will be built; promulgating and sharing of vulnerability knowledge will be easier; comparison and fusion of vulnerability information from different sources will be more efficient; moreover automated scanning and patching of vulnerabilities will lead to self-managing systems.
引用
收藏
页码:228 / 240
页数:13
相关论文
共 50 条
  • [41] Overview of the analytical Information markup language
    Chalk, Stuart
    ABSTRACTS OF PAPERS OF THE AMERICAN CHEMICAL SOCIETY, 2015, 249
  • [42] NQML: Natural Query Markup Language
    Parlikar, A
    Shrivastava, N
    Khullar, V
    Sanyal, S
    Proceedings of the 2005 IEEE International Conference on Natural Language Processing and Knowledge Engineering (IEEE NLP-KE'05), 2005, : 184 - 188
  • [43] Applications of chemical markup language.
    MurrayRust, P
    Rzepa, HS
    ABSTRACTS OF PAPERS OF THE AMERICAN CHEMICAL SOCIETY, 1997, 214 : 23 - COMP
  • [44] SQL markup language for enterprise integration
    Xu, YJ
    Shi, MH
    2004 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, PROCEEDINGS, 2004, : 413 - 416
  • [45] Test Case Markup Language for Visual Programming Language
    Jaafar, Mohd Farid
    Selamat, Mohd Hasan
    Ghani, Abdul Azim Abdul
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2007, 7 (09): : 45 - 52
  • [46] FMML: A Feature Model Markup Language
    Nabdel, Leili
    Karatas, Ahmet Serkan
    Oguztuzun, Halit
    Dogru, Ali
    NUMERICAL ANALYSIS AND APPLIED MATHEMATICS ICNAAM 2011: INTERNATIONAL CONFERENCE ON NUMERICAL ANALYSIS AND APPLIED MATHEMATICS, VOLS A-C, 2011, 1389
  • [47] SSML: A speech synthesis markup language
    Taylor, P
    Isard, A
    SPEECH COMMUNICATION, 1997, 21 (1-2) : 123 - 133
  • [48] A Content Markup Language for Data Services
    Noviello, C.
    Acampa, P.
    Furnari, Mango M.
    INFORMATION SYSTEMS DEVELOPMENT: TOWARDS A SERVICE PROVISION SOCIETY, 2009, : 559 - 567
  • [49] A short tutorial of the scenario markup language
    Gajananan, Kugamoorthy
    NII Technical Reports, 2013, (01):
  • [50] Path Markup Language for Indoor Navigation
    Cai, Yang
    Alber, Florian
    Hackett, Sean
    COMPUTATIONAL SCIENCE - ICCS 2020, PT VII, 2020, 12143 : 340 - 352