• DocumentCode
    3326615
  • Title

    Towards a Taxonomy of Vulnerabilities

  • Author

    Bazaz, Anil ; Arthur, James D.

  • Author_Institution
    Software Protection Platform Team, Microsoft Corp., Redmond, WA
  • fYear
    2007
  • fDate
    Jan. 2007
  • Abstract
    This paper presents a taxonomy of vulnerabilities created as a part of an effort to develop a framework for deriving verification and validation strategies to assess software security. This taxonomy is grounded in a process/object model of computation that establishes a relationship between software vulnerabilities, an executing process, and computer system resources such as memory, input/output, or cryptographic resources. That relationship promotes the concept that a software application is vulnerable to exploits when it permits the violation of (a) constraints imposed by computer system resources and/or (b) assumptions made about the usage of those resources. The taxonomy identifies and classifies these constraints and assumptions. The process/object model also serves as a basis for the classification scheme the taxonomy uses. That is, the computer system resources (or objects) identified in the process/object model form the categories and refined subcategories of the taxonomy. Vulnerabilities, which are expressed in the form of constraints and assumptions, are classified within the taxonomy according to these categories and subcategories. This taxonomy of vulnerabilities is novel and distinctively different from other taxonomies found in literature
  • Keywords
    operating systems (computers); program verification; resource allocation; security of data; computer system resource; object model; resource-based classification; software process; software security; software vulnerability; validation strategy; Application software; Computational modeling; Computer applications; Computer security; Cryptography; Data security; Software protection; Software testing; Taxonomy;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    System Sciences, 2007. HICSS 2007. 40th Annual Hawaii International Conference on
  • Conference_Location
    Waikoloa, HI
  • ISSN
    1530-1605
  • Electronic_ISBN
    1530-1605
  • Type

    conf

  • DOI
    10.1109/HICSS.2007.566
  • Filename
    4076705