科研成果详情

题名Vulnerabilities scoring approach for cloud saas
作者
发表日期2016-07-20
会议名称7th International Symposium on UbiCom Frontiers—Innovative Research, Systems and Technologies(UFirst 2015)
会议录名称Proceedings - 2015 IEEE 12th International Conference on Ubiquitous Intelligence and Computing, 2015 IEEE 12th International Conference on Advanced and Trusted Computing, 2015 IEEE 15th International Conference on Scalable Computing and Communications, 2015 IEEE International Conference on Cloud and Big Data Computing, 2015 IEEE International Conference on Internet of People and Associated Symposia/Workshops, UIC-ATC-ScalCom-CBDCom-IoP 2015
会议录编者Jianhua Ma, Laurence T. Yang, Huansheng Ning, and Ali Li
ISBN9781467372114
页码1339-1347
会议日期10-14 Aug. 2015
会议地点Beijing, China
出版者The Institute of Electrical and Electronics Engineers, Inc
摘要

It is known to be full of challenges to score vulnerabilities of cloud services developed by different third-party providers. Although there have been a few systems for scoring vulnerabilities (e.g., CVSS) of many existing softwares, most of them are unable to be leveraged to score vulnerabilities in cloud services, because they fail to consider some important factors located in the clouds such as business context (i.e., Dependency relationships between services). This paper presents VScorer, a novel security framework to score vulnerabilities in various cloud services based on different given requirements. By inputting concrete business context and security requirement into VScorer, cloud provider can get a ranking list of vulnerabilities in the business based on the given security requirement. Following the ranking list, cloud provider is able to patch the most critical vulnerabilities first. We developed a prototype and demonstrate VScorer can work better than current representative vulnerability scoring system CVSS.

DOI10.1109/UIC-ATC-ScalCom-CBDCom-IoP.2015.242
URL查看来源
收录类别CPCI-S
语种英语English
WOS研究方向Computer Science
WOS类目Computer Science, Artificial Intelligence ; Computer Science, Information Systems ; Computer Science, Interdisciplinary Applications ; Computer Science, Theory & Methods
WOS记录号WOS:000411670500218
Scopus入藏号2-s2.0-84983455849
引用统计
文献类型会议论文
条目标识符https://repository.uic.edu.cn/handle/39GCC9TT/13507
专题个人在本单位外知识产出
作者单位
School of EECS, Peking University, China, Key Laboratory of High Confidence Software Technologies, Ministry of Education, China
推荐引用方式
GB/T 7714
Li, Zhou,Tang, Cong,Hu, Jianbinet al. Vulnerabilities scoring approach for cloud saas[C]//Jianhua Ma, Laurence T. Yang, Huansheng Ning, and Ali Li: The Institute of Electrical and Electronics Engineers, Inc, 2016: 1339-1347.
条目包含的文件
条目无相关文件。
个性服务
查看访问统计
谷歌学术
谷歌学术中相似的文章
[Li, Zhou]的文章
[Tang, Cong]的文章
[Hu, Jianbin]的文章
百度学术
百度学术中相似的文章
[Li, Zhou]的文章
[Tang, Cong]的文章
[Hu, Jianbin]的文章
必应学术
必应学术中相似的文章
[Li, Zhou]的文章
[Tang, Cong]的文章
[Hu, Jianbin]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。