skip to main content
10.1145/1107622.1107652acmotherconferencesArticle/Chapter ViewAbstractPublication PagesinfoseccdConference Proceedingsconference-collections
Article

Overcoming programming flaws: indexing of common software vulnerabilities

Published:23 September 2005Publication History

ABSTRACT

The goal of this research project was to identify categories of programming flaws that lead to software bugs and index existing vulnerability reports against those categories. A keyword-based search placed 70% of the records from the OSVDB and CVE databases into 15 vulnerability categories. The results identified malformed data, buffer overflow and cross-site scripting as the top three issues. The project laid the foundations for future research into ways of mitigating programming flaws.

References

  1. Greenemeier, Larry. Homeland Security Needs Public-Private Cooperation. Information Week April 19, 2004. Accessed May 10, 2005 from http://www.informationweek.com/story/show/Article.jhtml?articleID=18902167.Google ScholarGoogle Scholar
  2. Common Vulnerabilities and Exposures Database. Accessed May 11, 2005 from http://www.eve.mitre.orgGoogle ScholarGoogle Scholar
  3. Open Source Vulnerability Database. Accessed May 23, 2005 from http://www.osvdb.org.Google ScholarGoogle Scholar
  4. Viega, J. and McGraw, G. Building Secure Software. Addison-Wesley, 2002.Google ScholarGoogle Scholar

Index Terms

  1. Overcoming programming flaws: indexing of common software vulnerabilities

    Recommendations

    Comments

    Login options

    Check if you have access through your login credentials or your institution to get full access on this article.

    Sign in

    PDF Format

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader