A Survey of Computer Vulnerability Assessment

Xing Xu · Chinese Journal of Computers · 2004

Computer vulnerability assessment has experienced the stage of manual to automatic. It’s now expanding from partial assessment to holistic, from rule based to model based, from single host to distributed. In the applications of computer security, assessing network’s vulnerabilities is usually required. To make the result comprehensive and accurate, the target of assessment must be considered as a whole system with dynamic and distributed features. The system is holistic both in time and space. The security of network system should be ensured as a whole all along rather than some host at sometime. The rule based assessing methods have been well studied. This is the base of the model based methods. At the same time, the model based methods have made rapid progress. Many model based methods start with different angles and have different advantages. For example, the Requires/Provides model can be suitable for attack generation and intrusion detection. Ritchey’s model is more efficient for describing the exploitation of well known network vulnerabilities than other models. Ramakrishnan’s model is fit for analyzing system vulnerabilities from local host.Further researches could focus on the following aspects: to build new models, to refine the existing models or the analyzing methods. Such three aspects are not completely independent. When building or refining a model, the factors relevant to security of actual systems could be added to the model step by step so that the model can solve actual problems more powerfully. Many methods might be introduced to analyze a security model,such as temporal logic, CPN and SHLPN (stochastic High level Petri net). And these can provide powerful mathematic tools for formal analysis of security models.

Read the paper · More papers on PaperTik