An XML-based data model for vulnerability assessment reports

被引:0
作者
Valvis, G [1 ]
Polemi, D [1 ]
机构
[1] Univ Pireaus, Dept Informat, Piraeus, Greece
来源
Challenges of Expanding Internet: E-Commerce, E-Business, and E-Government | 2005年 / 189卷
关键词
vulnerability assessment; XML modeling;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Periodic vulnerability assessment (VA), used to uncover and correct vulnerabilities, is a common intrusion prevention technique. Although the VA tools that perform those assessments, report similar information, there are tool specific differences. Unfortunately, trying to combine the output of these tools would require separate parsing tools to address the significant low-level differences. A new data model (Vulnerability Assessment Report Format VARF) is presented in this paper in order to define data formats for sharing information of interest to VA and to facilitate the interaction with the risk management process. As a proof of concept a set of XSLT transformations was built in order to transform the results of an open source VA tool to a VARF compliant report enabling further processing of the results.
引用
收藏
页码:513 / 526
页数:14
相关论文
共 9 条
[1]  
*CERT COORD CTR, 2004, OV ATTAK TRENDS
[2]   Unraveling the Web services Web - An introduction to SOAP, WSDL, and UDDI [J].
Curbera, F ;
Duftler, M ;
Khalaf, R ;
Nagy, W ;
Mukhi, N ;
Weerawarana, S .
IEEE INTERNET COMPUTING, 2002, 6 (02) :86-93
[3]  
GRAPHVIZ, 2004, OPEN SOURCE GRAH DRA
[4]  
MANN D, 1999, COMMON ENUMERATOIN V
[5]  
*OPENSEC, 2005, OP SEC PROJ
[6]  
*XCCDF, 2005, SPEC
[7]  
2004, OPEN VULERNABILITY A
[8]  
2005, NESSUS VULNERABILITY
[9]  
2004, SECURITYFOCUS BUGTRA