Formal Definition and Categprization of Vulnerabilities using Take-Grant Protection Model

سال انتشار: 1385
نوع سند: مقاله کنفرانسی
زبان: انگلیسی
مشاهده: 1,707

استخراج به نرم افزارهای پژوهشی:

لینک ثابت به این مقاله:

شناسه ملی سند علمی:

ACCSI12_364

تاریخ نمایه سازی: 23 دی 1386

چکیده مقاله:

In this paper, we first propose formal definitions of vulnerability , exploit , and attak in computer systems. The presented definition of vulnerability is based on its likely effect on the system. Which is often overlooked. Then we suggest an impact based categorization of vulnerabilities and their formal definition model to define the categories , the categorization is independent of take-grant protection models. A broad examples of vulnerabilities are presented to show the categorization usefulness.

نویسندگان

Hamid Reza Sharriari

Network Security Center, Department of Computer Engineering, Sharif University of Technology, Tehran, Iran

Rasool Jalili

Network Security Center, Department of Computer Engineering, Sharif University of Technology, Tehran, Iran