Being Explicit About Security Weaknesses

Robert A. Martin · 2007

that are found in today’s products. As an alternate approach, under sponsorship of DHS NCSD, and as part of MITRE’s participation in the DHS-sponsored NIST SAMATE effort, MITRE investigated the possibility of leveraging the Common Vulnerabilities and Exposures (CVE) initiative’s experience in analyzing more than 20,000 real-world vulnerabilities reported and discussed by industry and academia. As part of the creation of the CVE list [4] that is used as the source of vulnerabilities for the National Vulnerability Database [5], MITRE’s CVE initiative during the last six years has developed a preliminary classification and categorization of vulnerabilities, attacks, faults, and other concepts that can be used to help define this arena. However, the original groupings used in the development of CVE, while sufficient for that task, were too rough to be used to identify and categorize the functionality found within the offerings of the code security assessment industry. For example, in order to support the development of CVE content, it is sufficient to separate the reported vulnerabilities in products into working categories such as weak/bad authentication,

Read the paper · More papers on PaperTik