Tree Approach to Vulnerability Classification


Citation

Paper

Abstract

We present a classification scheme based on conditions which must hold for a vulnerability to exist. This scheme allows for vulnerabilities to fall into multiple classes without ambiguity, and enables analysts to focus on the causes of vulnerabilities. We use a tree-based approach to organize these conditions at different levels of abstraction.

Background

This is some work from our vulnerabilities analysis project.