摘要
软件脆弱性是系统安全受到各种威胁的根本原因。从软件脆弱性的本质出发,对脆弱性进行研究是一个新课题。本文分析了各种软件脆弱性的定义,并基于脆弱性引入原因、所在部件、产生的影响、修复、验证、检测和攻击等关键属性,提出了对软件脆弱性的多维描述方法。
The system security is threatened by software vulnerabilities. It is a new subject to research on the vulnerabilities from the angle of essence. The paper analyses the definitions of various software vulnerabilities, and puts forward a multi-dimensional description method for software vulnerabilities on the basis of the key attributes of vulnerability cause, component, impact, patch, validation, detection and attack.
出处
《计算机工程与科学》
CSCD
2004年第11期33-36,共4页
Computer Engineering & Science