科技报告详细信息
A Formal Model for A System's Attack Surface
Manadhata, Pratyusa K. ; Wing, Jeannette M.
HP Development Company
关键词: attack surface;    attack surface metric;    io automata;    security metrics;   
RP-ID  :  HPL-2011-115
学科分类:计算机科学(综合)
美国|英语
来源: HP Labs
PDF
【 摘 要 】

Practical software security metrics and measurements are essential for secure software development. In this chapter, we introduce the measure of a software system's attack surface as an indicator of the system's security. The larger the attack surface, the more insecure the system. We formalize the notion of a system's attack surface using an I/O automata model of the system and introduce an attack surface metric to measure the attack surface in a systematic manner. Our metric is agnostic to a software system's implementation language and is applicable to systems of all sizes. Software developers can use the metric in multiple phases of the software development process to improve software security. Similarly, software consumers can use the metric in their decision making process to compare alternative software.

【 预 览 】
附件列表
Files Size Format View
RO201804100002866LZ 422KB PDF download
  文献评价指标  
  下载次数:18次 浏览次数:26次