首页 | 本学科首页   官方微博 | 高级检索  
     检索      

面向SaaS云平台的安全漏洞评分方法研究
引用本文:李 舟,唐 聪,胡建斌,陈 钟.面向SaaS云平台的安全漏洞评分方法研究[J].通信学报,2016,37(8):157-166.
作者姓名:李 舟  唐 聪  胡建斌  陈 钟
作者单位:北京大学信息科学技术学院,北京 100871
基金项目:国家自然科学基金资助项目(No.61272519, No.61170297, No.61572080, No.61472258)
摘    要:对不同的第三方提供的云服务进行漏洞评分是一项充满挑战的任务。针对一些基于云平台的重要因素,例如业务环境(业务间的依赖关系等),提出了一种新的安全框架VScorer,用于对基于不同需求的云服务进行漏洞评分。通过对VScorer输入具体的业务场景和安全需求,云服务商可以在满足安全需求的基础上获得一个漏洞排名。根据漏洞排名列表,云服务提供商可以修补最关键的漏洞。在此基础上开发了VScorer的原型,并且证实它比现有最具有代表性的安全漏洞评分系统CVSS表现得更为出色。

关 键 词:SaaS  云服务  漏洞评分系统  CVSS

Vulnerabilities scoring approach for cloud SaaS
Zhou LI,Cong TANG,Jian-bin HU,Zhong CHEN.Vulnerabilities scoring approach for cloud SaaS[J].Journal on Communications,2016,37(8):157-166.
Authors:Zhou LI  Cong TANG  Jian-bin HU  Zhong CHEN
Institution:School of EECS,Peking University,Beijing 100871,China
Abstract:There are full of challenges to score vulnerabilities of cloud services developed by different third-party providers. Although there have been a few systems for scoring vulnerabilities (e. g., CVSS) of many existing software, most of them are unable to be leveraged to score vulnerabilities in cloud services, because they fail to consider some important factors located in the clouds such as business context (i. e ., dependency relationships between services). VScorer, a novel security frame work to score vulnerabilities in various cloud services were presented based on different given requirements. By inputting concrete business context and security requirement into VScorer, cloud provider can get a ranking list of vulnerabilities in the business based on the given security requirement. Following the ranking list, cloud provider was able to patch the most critical vulnerabilities first. A prototype was developed and VScorer can be demonstrazed to work better than current representative vulnerability scoring system CVSS.
Keywords:SaaS  cloud service  vulnerability scoring system  CVSS
点击此处可从《通信学报》浏览原始摘要信息
点击此处可从《通信学报》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号