Cryptography Classes in Bugs Framework (BF): Encryption Bugs (ENC), Verification Bugs (VRF), and Key Management Bugs (KMN)

被引:0
|
作者
Bojanova, Irena [1 ]
Yesha, Yaacov [1 ,2 ]
机构
[1] NIST, Gaithersburg, MD 20899 USA
[2] UMBC, Baltimore, MD USA
关键词
software weaknesses; bug taxonomy; attacks;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Accurate, precise, and unambiguous definitions of software weaknesses (bugs) and clear descriptions of software vulnerabilities are vital for building the foundations of cybersecurity. The Bugs Framework (BF) comprises rigorous definitions and (static) attributes of bug classes, along with their related dynamic properties, such as proximate, secondary and tertiary causes, consequences, and sites. This paper presents an overview of previously developed BF classes and the new cryptography related classes: Encryption Bugs (ENC), Verification Bugs (VRF), and Key Management Bugs (KMN). We analyze corresponding vulnerabilities and provide their clear descriptions by applying the BF taxonomy. We also discuss the lessons learned and share our plans for expanding BF.
引用
收藏
页数:8
相关论文
共 4 条
  • [1] The Bugs Framework (BF): A Structured Approach to Express Bugs
    Bojanova, Irena
    Black, Paul E.
    Yesha, Yaacov
    Wu, Yan
    2016 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY (QRS 2016), 2016, : 175 - 182
  • [2] Randomness Classes in Bugs Framework (BF): True-Random Number Bugs (TRN) and Pseudo-Random Number Bugs (PRN)
    Bojanova, Irena
    Yesha, Yaacov
    Black, Paul E.
    2018 IEEE 42ND ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), VOL 1, 2018, : 738 - 745
  • [3] Information Exposure (IEX): A New Class in the Bugs Framework (BF)
    Bojanova, Irena
    Yesha, Yaacov
    Black, Paul E.
    Wu, Yan
    2019 IEEE 43RD ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), VOL 1, 2019, : 559 - 564
  • [4] The MPI BUGS INITIATIVE: a Framework for MPI Verification Tools Evaluation
    Laurent, Mathieu
    Saillard, Emmanuelle
    Quinson, Martin
    PROCEEDINGS OF FIFTH INTERNATIONAL WORKSHOP ON SOFTWARE CORRECTNESS FOR HPC APPLICATIONS (CORRECTNESS 2021), 2021, : 16 - 24