摘要
通过对计算机公共弱点/风险(CVE)列表所列漏洞进行了深入分析的基础上,依据对漏洞抽象层次和漏洞看待角度的不同,建立了多种CVE体系结构,包括树形结构、视角三维、产生三维等,并给出了由有穷自动机实现的CVE树形结构的形式化描述.CVE体系结构的建立对理解、避免、检测和消除计算机系统漏洞具有理论和实践意义.
This paper does a deep analysis of Common Vulnerabilities and Exposures(CVE). On the base of it, a CVE structure according to manifold points of view and abstract grades, such as tree structure viewing three - dimensio structure and occurring structure is constructed. Then a formal description using for the tree structure is provided. This CVE structure is valuable for the understanding, avoiding, detecting and removing of vulnerabilities and exposures.
出处
《哈尔滨理工大学学报》
CAS
2003年第4期67-70,共4页
Journal of Harbin University of Science and Technology
基金
黑龙江省自然科学基金资助(F0204)