Finally, the paper is published in IEEE. Check it out at http://ieeexplore.ieee.org/xpl/freeabs_all.jsp?arnumber=6122789
The abstract:
Since early 90s, experts have proposed various ways to prevent exploitations and avoid releasing software with vulnerabilities. One way is through educating developers with information on known vulnerabilities using taxonomy of vulnerabilities as a guide. However, the guide using taxonomy of vulnerabilities has not shown to mitigate the issues. One possibility is due to the existence of gaps in producing the right and comprehensive taxonomy for software vulnerabilities. We studied various available taxonomies on software vulnerabilities. In this paper we propose and discuss our own criteria for taxonomy of software vulnerabilities with some improvement with particular emphasis on C programming.
The paper has been presented at IAS 2011, Melaka, Malaysia on Dec 5th - Dec 8th 2011.
Thursday, January 12, 2012
Home »
Buffer Overflow
,
C Programs
,
Comparison
,
Conference
,
Information Security
,
Publications
,
Security Forum/Conference
,
Software Security
» Understanding Vulnerabilities by Refining Taxonomy
0 comments:
Post a Comment