首页    期刊浏览 2025年06月26日 星期四
登录注册

文章基本信息

  • 标题:Vulnerability Assessment Enhancement for Middleware for Computing and Informatics
  • 其他标题:Vulnerability Assessment Enhancement for Middleware for Computing and Informatics
  • 作者:Serrano, Jairo ; Heymann, Elisa ; Cesar, Eduardo
  • 期刊名称:COMPUTING AND INFORMATICS
  • 印刷版ISSN:1335-9150
  • 出版年度:2012
  • 卷号:31
  • 期号:1
  • 页码:103-118
  • 语种:English
  • 出版社:COMPUTING AND INFORMATICS
  • 摘要:Security on Grid computing is often an afterthought. However assessing security of middleware systems is of the utmost importance because they manage critical resources owned by different organizations. To fulfill this objective we use First Principles Vulnerability Assessment (FPVA), an innovative analystic-centric (manual) methodology that goes beyond current automated vulnerability tools. FPVA involves several stages for characterizing the analyzed system and its components. Based on the evaluation of several middleware systems, we have found that there is a gap between the initial and the last stages of FPVA, which is filled with the security practitioner expertise. We claim that this expertise is likely to be systematically codified in order to be able to automatically indicate which, and why, components should be assessed. In this paper we introduce key elements of our approach: Vulnerability graphs, Vulnerability Graph Analyzer, and a Knowledge Base of security configurations.
  • 关键词:Grid; middleware; security; vulnerability assessment; vulnerability break graph
Loading...
联系我们|关于我们|网站声明
国家哲学社会科学文献中心版权所有