Searching for just a few words should be enough to get started. If you need to make more complex queries, use the tips below to guide you.
Article type: Research Article
Authors: Fourney, Robert S.; * | Hanson, Austin D.
Affiliations: Department of Electrical Engineering and Computer Science, HH 215, Box 2220, South Dakota State University, Brookings, SD 57007, USA
Correspondence: [*] Corresponding author. Tel.: +1 605 688 4016; Fax: +1 605 688 4401; E-mail: Robert.Fourney@ieee.org.
Abstract: We present our experience in developing an open source tool for the measurement of security flaws. Since security flaws result from the unauthorized flow of information, our tool shows how these flaws can be measured and compared based on the amount of information that flows, how “far” it flows, and the value of the information. Flaws can then be compared and careful security testers can maximize the amount of security for a limited set of resources. The development of a tool to partially automate this process will prove to be an asset to the open source community in that the “many eyes” can be directed and these resources prioritized in order to patch flaws in the most efficient manner and minimize downtime and risk.
Keywords: Security, information flow, tool, database
DOI: 10.3233/JCM-2009-0242
Journal: Journal of Computational Methods in Sciences and Engineering, vol. 9, no. s2, pp. S137-S147, 2009
IOS Press, Inc.
6751 Tepper Drive
Clifton, VA 20124
USA
Tel: +1 703 830 6300
Fax: +1 703 830 2300
sales@iospress.com
For editorial issues, like the status of your submitted paper or proposals, write to editorial@iospress.nl
IOS Press
Nieuwe Hemweg 6B
1013 BG Amsterdam
The Netherlands
Tel: +31 20 688 3355
Fax: +31 20 687 0091
info@iospress.nl
For editorial issues, permissions, book requests, submissions and proceedings, contact the Amsterdam office info@iospress.nl
Inspirees International (China Office)
Ciyunsi Beili 207(CapitaLand), Bld 1, 7-901
100025, Beijing
China
Free service line: 400 661 8717
Fax: +86 10 8446 7947
china@iospress.cn
For editorial issues, like the status of your submitted paper or proposals, write to editorial@iospress.nl
如果您在出版方面需要帮助或有任何建, 件至: editorial@iospress.nl