DocumentCode :
1122542
Title :
Taxonomies of attacks and vulnerabilities in computer systems
Author :
Igure, Vinay M. ; Williams, Ronald D.
Author_Institution :
Virginia Univ., Charlottesville, VA
Volume :
10
Issue :
1
fYear :
2008
Firstpage :
6
Lastpage :
19
Abstract :
Security assessment of a system is a difficult problem. Most of the current efforts in security assessment involve searching for known vulnerabilities. Finding unknown vulnerabilities still largely remains a subjective process. The process can be improved by understanding the characteristics and nature of known vulnerabilities. The knowledge thus gained can be organized into a suitable taxonomy, which can then be used as a framework for systematically examining new systems for similar but as yet unknown vulnerabilities. There have been many attempts at producing such taxonomies. This article provides a comprehensive survey of the important work done on developing taxonomies of attacks and vulnerabilities in computer systems. This survey covers work done in security related taxonomies from 1974 until 2006. Apart from providing a state-of-the-art survey of taxonomies, we also analyze their effectiveness for use in a security assessment process. Finally, we summarize the important properties of various taxonomies to provide a framework for organizing information about known attacks and vulnerabilities into a taxonomy that would benefit the security assessment process.
Keywords :
telecommunication security; computer system attacks; computer system vulnerabilities; information organization; security assessment; taxonomies; Buildings; Communication system security; Data security; Databases; Information security; Organizing; Standards publication; Taxonomy;
fLanguage :
English
Journal_Title :
Communications Surveys & Tutorials, IEEE
Publisher :
ieee
ISSN :
1553-877X
Type :
jour
DOI :
10.1109/COMST.2008.4483667
Filename :
4483667
Link To Document :
بازگشت