摘要
针对美国国家漏洞数据库(National Vulnerability Database,NVD)中开源软件的漏洞,设计并实现了漏洞补丁采集与分析系统。该系统能自动采集漏洞补丁文件,生成漏洞补丁库。基于漏洞补丁数据,提取补丁特征并进行分类整理,为不同类型漏洞提供有效的漏洞检测方法等研究提供了数据和分析基础。
This paper presents a software vulnerability patch collection and analysis system for vulnerabilities of open source software in the National Vulnerability Database (NVD). The system collects vulnerability patches automatically and generates the vulnerability patch database. It extracts the patch features from the vulnerability patches and then classifies and orders them. The system can provide the data and analysis basis for the study of effective vulnerability detection approaches for different types of vulnerabilities.
作者
邹雅毅
李珍
ZOU Ya-yi LI Zhen(Class 1 Senior 2, High School Attached to Huazhong University of Science and Technology ,Wuhan Hubei 430074, China School of Computer Science and Technology , Huazhong University of Science and Technology , Wuhan Hubei 430074,China)
出处
《河北省科学院学报》
CAS
2016年第3期18-22,共5页
Journal of The Hebei Academy of Sciences
关键词
软件漏洞
补丁
漏洞库
Software vulnerability
Patch
Vulnerability database