论文标题

安全配置的脆弱性覆盖范围

Vulnerability Coverage for Secure Configuration

论文作者

Dass, Shuvalaxmi, Namin, Akbar Siami

论文摘要

我们提出了一个关于``{漏洞覆盖率}''的充分测试的新颖想法。引入的覆盖范围措施研究了在国家漏洞数据库(NVD)网站上经常发现的某些类别的漏洞的基础软件。通过适应进化算法,即遗传算法(GA)和粒子群优化(PSO),进行了测试输入生成过程的彻底性。该方法利用了共同的漏洞评分系统(CVSS),这是评估计算机系统安全漏洞严重性的免费和开放行业标准,作为测试输入生成的适应性措施。然后评估这些进化算法的结果,以确定与测试目的相匹配的漏洞模式的漏洞。

We present a novel idea on adequacy testing called ``{vulnerability coverage}.'' The introduced coverage measure examines the underlying software for the presence of certain classes of vulnerabilities often found in the National Vulnerability Database (NVD) website. The thoroughness of the test input generation procedure is performed through the adaptation of evolutionary algorithms namely Genetic Algorithms (GA) and Particle Swarm Optimization (PSO). The methodology utilizes the Common Vulnerability Scoring System (CVSS), a free and open industry standard for assessing the severity of computer system security vulnerabilities, as a fitness measure for test inputs generation. The outcomes of these evolutionary algorithms are then evaluated in order to identify the vulnerabilities that match a class of vulnerability patterns for testing purposes.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源