Announcements

Center for Information Protection
UC Davis is planning to join the NSF I/UCRC Center for Information Protection. We are looking for companies to join our Industrial Advisory Board.
Find out more here!

Conferences and Workshops


My Links


Other Links


This Quarter’s Classes


Office Hours for This Quarter


Contacting Me

Tree Approach to Vulnerability Classification


Citation

  • S. Engle, S. Whalen, D. Howard, and M. Bishop, “Tree Approach to Vulnerability Classification”, Technical Report CSE-2006-10, Dept. of Computer Science, University of California at Davis, Davis, CA 95616-8562 (May 2006).

Paper

Abstract

We present a classification scheme based on conditions which must hold for a vulnerability to exist. This scheme allows for vulnerabilities to fall into multiple classes without ambiguity, and enables analysts to focus on the causes of vulnerabilities. We use a tree-based approach to organize these conditions at different levels of abstraction.

Background

This is some work from our vulnerabilities analysis project.


Valid HTML 4.01 Transitional Built with BBEdit Built on a Macintosh
Last updated on Monday, July 20, 2009 at 10:33:12AM PDT