• DocumentCode
    3223264
  • Title

    An empirical property-based model for vulnerability analysis and evaluation

  • Author

    Le, Ha Thanh ; Subramanian, Deepak ; Hsu, Wen Jing ; Loh, Peter Kok Keong

  • Author_Institution
    Sch. of Comput. Eng., Nanyang Technol. Univ., Singapore, Singapore
  • fYear
    2009
  • fDate
    7-11 Dec. 2009
  • Firstpage
    40
  • Lastpage
    45
  • Abstract
    This work presents an empirical property-based model to describe Web-based vulnerability. We define a web application using a new descriptive model with pre-condition, behavior, entity and communication property sets. The vulnerable property relationship graph (VPRG) defines a vulnerability as vulnerable properties in application with relations to other properties in cause- and consequence-relationships. The Vulnerable Property Relationship Matrix (VPRM) is used to quantify the existence vulnerability and to measure its impact according to the relations of vulnerable properties to other properties in execution of the web application. A severity score calculation is proposed based on VPRM: the vulnerability severity score is typically the sum of consequence as a result of state changes of every evolving property in the vulnerable property relationship model. The prototype model is applied to a case study involving specified Web vulnerabilities.
  • Keywords
    Internet; graph theory; security of data; Web-based vulnerability; cause-consequence-relationships; empirical property-based model; severity score calculation; vulnerable property relationship graph; vulnerable property relationship model; Application software; Computer languages; Databases; Engines; Prototypes; Risk analysis; Web server; severity score; vulnerable property relationship graph (VPRG); vulnerable property relationship matrix (VPRM); web application vulnerability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Services Computing Conference, 2009. APSCC 2009. IEEE Asia-Pacific
  • Conference_Location
    Singapore
  • Print_ISBN
    978-1-4244-5338-2
  • Electronic_ISBN
    978-1-4244-5336-8
  • Type

    conf

  • DOI
    10.1109/APSCC.2009.5394144
  • Filename
    5394144