Sharing Vulnerability Information using a Taxonomically-correct, Web-based Cooperative Database
LingXi Ma, Salvador Mandujano, Ganlu Song, Pascal Charles Meunier · 2001
Software vulnerabilities are potential attack points in computing systems that can lead to considerable losses and severe security incidents. The way in which the information describing these vulnerabilities is handled is extremely important as vulnerability data are very sensitive and therefore should be disclosed to the right people in the right circumstances. However, information sharing is currently mostly unidirectional; the present paper discusses a new approach for handling software vulnerability information: a cooperative system supported by a vulnerability classification. The system is composed of internal protocols that determine state transitions through which new vulnerability information is submitted, classified, verified, and made available via a Web Interface.