论文部分内容阅读
提出一种基于XML的Web应用安全漏洞统一描述语言UVDL,通过制定包含漏洞信息的结构化XML文件,其中每个漏洞又以树状结构包含漏洞的基本信息、利用、影响、修复以及参考信息等框架文件,并定义各描述子项,来标准化漏洞检测过程.相比已有的漏洞描述语言,UVDL框架文件的插件组织形式更具灵活性和扩展能力,每个漏洞的分框架文件在Web漏洞检测系统的应用中更具可操作性.UVDL在考虑环境与状态错误对Web应用软件造成安全影响的基础上增加了Web漏洞分类、漏洞的严重程度以及利用性等属性信息.UVDL在漏洞评估系统中的应用实验表明,UVDL作为一种统一标准且易操作的漏洞描述语言,能够整合漏洞信息,解决多安全部件的协同工作和兼容性等问题.
This paper proposes a UMLL, a universal description language for Web application security vulnerabilities based on XML. By defining a structured XML file containing the vulnerability information, each of the vulnerabilities also contains the basic information, exploit, influence, repair, and reference information of the vulnerability in a tree structure Framework files, and define the description of the sub-items to standardize the vulnerability detection process.Compared with the existing vulnerability description language, UVDL framework file plug-in organization forms more flexibility and scalability, each vulnerability sub-framework file in the Web vulnerability Detection system more practical application.UVDL to consider the environmental and state errors on the Web application software to create a safety impact on the basis of the Web vulnerability classification, vulnerability severity and availability of attribute information.UVDL in the vulnerability assessment system The application experiments show that UVDL, as a unified and easy-to-use vulnerability description language, can integrate vulnerability information and solve the problems of multi-security components’ cooperation and compatibility.