ACM Home Page
Please provide us with feedback. Feedback
Assessing computer security vulnerability
Full text PdfPdf (790 KB)
Source ACM SIGOPS Operating Systems Review archive
Volume 29 ,  Issue 3  (July 1995) table of contents
Pages: 3 - 13  
Year of Publication: 1995
ISSN:0163-5980
Authors
Jim Alves-Foss  Laboratory for Applied Logic, Department of Computer Science, University of Idaho
Salvador Barbosa  Laboratory for Applied Logic, Department of Computer Science, University of Idaho
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 3,   Downloads (12 Months): 69,   Citation Count: 2
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/206826.206829
What is a DOI?

ABSTRACT

The lack of a standard gauge for quantifying computer system vulnerability is a hindrance to communicating information about vulnerabilities, and is thus a hindrance to reducing those vulnerabilities. The inability to address this issue through uniform semantics often leads to uncoordinated efforts at combating exposure to common avenues of exploitation. The de-facto standard for evaluating computer security is the government's Trusted Computer Evaluation Criteria, also known as the Orange Book. However, it is a generally accepted fact that the majority of non-government multi-user computer systems are classified into one of its two lower classes. The link between the higher classes and government classified data, makes the measure unsuitable for commercial use.This project presents a feasible approach for resolving this problem by introducing a standardized assessment. It introduces a method, termed the System Vulnerability Index (SVI), that analyzes a number of factors that affect security. These factors are evaluated and combined, through the use of special rules, to provide a measure of vulnerability. The strength of this method is in its abstraction of the problem, which makes it applicable to various operating systems and hardware implementations. User and superuser actions, as well as clues to a potentially breached state of security, serve as the basis for the security relevant factors. Facts for assessment are presented in a form suitable for implementation in a rule-based expert system.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
[1] D. Denning, Cryptography and Data Security, Addison-Wesley, Reading, MA 1981.
 
2
 
3
 
4
[4] B. Landreth, Out of the Inner Circle, Tempus Books (Microsoft Press), Redmond, WA, 1989.
 
5
 
6
 
7
[7] C. Stoll, The Cuckoo's Egg, Doubleday, NY, NY, 1989.
 
8
[8] "Department of Defense Trusted Computer System Evaluation Criteria," DoD 5200.28- STD, December 1985.


Collaborative Colleagues:
Jim Alves-Foss: colleagues
Salvador Barbosa: colleagues