• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2006, Vol. 28 ›› Issue (10): 11-12.

• 论文 • 上一篇    下一篇

安全漏洞的统一描述研究

杨阔朝 蒋凡   

  • 出版日期:2006-10-01 发布日期:2010-05-20

  • Online:2006-10-01 Published:2010-05-20

摘要:

安全漏洞统一格式描述可以使不同的安全产品从同一描述进行漏洞信息的更新,减少了不同安全产品公司各自维护漏洞库的投入,达到了不同厂家安全产品漏洞信息的同步与数据描述的一致。本文叙述了利用XML进行安全漏洞统一格式描述的GVML实现及其在安全产品中的应用。

关键词: 网络安全 漏洞 XML

Abstract:

The uniform description of security vulnerabilities can make security vulnerabilities of different security products update from the same description. It not only decreases the cost of different vendors in the maintenance of respective vulnerability databases, but also makes security vulnerabilities of different security products update at the same time and in the uniform description. This paper presents GVML(Global Vulnerability Markup Language)as a uniform description of security vulnerabilities using XML and its use in security products.

Key words: network security, security vulnerability, XML