| Assessing computer security vulnerability |
| Full text |
Pdf
(790 KB)
|
| Source
|
ACM SIGOPS Operating Systems Review
archive
Volume 29 , Issue 3 (July 1995)
table of contents
Pages: 3 - 13
Year of Publication: 1995
ISSN:0163-5980
|
|
Authors
|
|
Jim Alves-Foss
|
Laboratory for Applied Logic, Department of Computer Science, University of Idaho
|
|
Salvador Barbosa
|
Laboratory for Applied Logic, Department of Computer Science, University of Idaho
|
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 3, Downloads (12 Months): 69, Citation Count: 2
|
|
|
ABSTRACT
The lack of a standard gauge for quantifying computer system vulnerability is a hindrance to communicating information about vulnerabilities, and is thus a hindrance to reducing those vulnerabilities. The inability to address this issue through uniform semantics often leads to uncoordinated efforts at combating exposure to common avenues of exploitation. The de-facto standard for evaluating computer security is the government's Trusted Computer Evaluation Criteria, also known as the Orange Book. However, it is a generally accepted fact that the majority of non-government multi-user computer systems are classified into one of its two lower classes. The link between the higher classes and government classified data, makes the measure unsuitable for commercial use.This project presents a feasible approach for resolving this problem by introducing a standardized assessment. It introduces a method, termed the System Vulnerability Index (SVI), that analyzes a number of factors that affect security. These factors are evaluated and combined, through the use of special rules, to provide a measure of vulnerability. The strength of this method is in its abstraction of the problem, which makes it applicable to various operating systems and hardware implementations. User and superuser actions, as well as clues to a potentially breached state of security, serve as the basis for the security relevant factors. Facts for assessment are presented in a form suitable for implementation in a rule-based expert system.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
[1] D. Denning, Cryptography and Data Security, Addison-Wesley, Reading, MA 1981.
|
| |
2
|
|
| |
3
|
|
| |
4
|
[4] B. Landreth, Out of the Inner Circle, Tempus Books (Microsoft Press), Redmond, WA, 1989.
|
| |
5
|
|
| |
6
|
|
| |
7
|
[7] C. Stoll, The Cuckoo's Egg, Doubleday, NY, NY, 1989.
|
| |
8
|
[8] "Department of Defense Trusted Computer System Evaluation Criteria," DoD 5200.28- STD, December 1985.
|
|