Vulnerability Coverage for Secure Configuration

06/14/2020
by   Shuvalaxmi Dass, et al.
0

We present a novel idea on adequacy testing called “vulnerability coverage.” The introduced coverage measure examines the underlying software for the presence of certain classes of vulnerabilities often found in the National Vulnerability Database (NVD) website. The thoroughness of the test input generation procedure is performed through the adaptation of evolutionary algorithms namely Genetic Algorithms (GA) and Particle Swarm Optimization (PSO). The methodology utilizes the Common Vulnerability Scoring System (CVSS), a free and open industry standard for assessing the severity of computer system security vulnerabilities, as a fitness measure for test inputs generation. The outcomes of these evolutionary algorithms are then evaluated in order to identify the vulnerabilities that match a class of vulnerability patterns for testing purposes.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/14/2020

Vulnerability Coverage as an Adequacy Testing Criterion

Mainstream software applications and tools are the configurable platform...
research
01/03/2018

A Look at the Time Delays in CVSS Vulnerability Scoring

This empirical paper examines the time delays that occur between the pub...
research
12/28/2016

Optimization of Test Case Generation using Genetic Algorithm (GA)

Testing provides means pertaining to assuring software performance. The ...
research
07/21/2023

Vulnerability Detection Through an Adversarial Fuzzing Algorithm

Fuzzing is a popular vulnerability automated testing method utilized by ...
research
06/30/2020

Autosploit: A Fully Automated Framework for Evaluating the Exploitability of Security Vulnerabilities

The existence of a security vulnerability in a system does not necessari...
research
09/24/2020

ThreatZoom: CVE2CWE using Hierarchical Neural Network

The Common Vulnerabilities and Exposures (CVE) represent standard means ...

Please sign up or login with your details

Forgot password? Click here to reset