Monday March 19, 2007
Dave's Bit BucketDave Walker's jottings - mostly pertaining to security Vulnerability Description Languages and Classifications - Empirical Validation of Muffett's Second Law? Way back when - at least 8 years ago, by my recollection - my pal Alec posted the first disclosure of "Muffett's Second Law", which states: "There are no new security bugs, there are merely ever-more-complex reincarnations of the same classes of bug." While this appears to fly in the face of a huge plethora of vulnerability disclosures at first sight, there's method behind this. Consider the ways in which vulnerabilities can readily be grouped:
The fact that a vulnerability description language has emerged to handle structured vulnerability disclosures, and a dictionary of terms is being compiled to assist with consistency of same, suggests that this particular Muffett's Law has a good degree of truth behind it... (2007-03-19 07:28:15.0) Permalink Comments [3]
Trackback URL: http://blogs.sun.com/davew/entry/vulnerability_description_languages_and_classifications
Post a Comment: |
Calendar
RSS Feeds
All /Cooking /General /Java /Networking /Security Search | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Posted by alecm on March 19, 2007 at 05:26 PM GMT #
Or, putting it another way, what set of categories would you use to classify vulnerabilities?
Posted by Dave Walker on March 19, 2007 at 06:38 PM GMT #
Posted by alecm on March 20, 2007 at 11:51 AM GMT #