Difference between revisions of "SVG:Vulnerability Assessment"
Line 1: | Line 1: | ||
{{svg-header}} | {{svg-header}} | ||
Vulnerability Assessment is the proactive examination of software in order to find vulnerabilities that may exist. This is carried out by some members of SVG from collaborating projects and partners. | Vulnerability Assessment is the proactive examination of software in order to find vulnerabilities that may exist. This is carried out by some members of SVG from collaborating projects and partners. | ||
Line 12: | Line 12: | ||
Information on their work is available from the University of | Information on their work is available from the University of | ||
Wisconsin [http://www.cs.wisc.edu/mist/includes/vuln.html Vulnerability Assessment] | Wisconsin [http://www.cs.wisc.edu/mist/includes/vuln.html Vulnerability Assessment] page | ||
== Other information == | == Other information == | ||
More information will be added later. | |||
See also EGEE/GridPP information at: | See also EGEE/GridPP information at: | ||
* [http://www.gridpp.ac.uk/gsvg/testing/index.html EGEE/GridPP Vulnerability Detection] | * [http://www.gridpp.ac.uk/gsvg/testing/index.html EGEE/GridPP Vulnerability Detection] |
Revision as of 17:52, 3 November 2010
Main page | Software Security Checklist | Issue Handling | Advisories | Notes On Risk | Advisory Template | More |
Vulnerability Assessment
Vulnerability Assessment is the proactive examination of software in order to find vulnerabilities that may exist. This is carried out by some members of SVG from collaborating projects and partners.
Assessment may be considered prior to allowing new software to be deployed on the EGI infrastructure to help minimize the introduction of new vulnerabilities
First Principles Vulnerability Assessment
Members of the University of Wisconsin / Universitat Autònoma de Barcelona Middleware Security and Testing Group have developed First Principles Vulnerability Assessment techniques for assessing software for vulnerabilities and carried out assessments of several major middleware systems, found significant vulnerabilities in many of them, then helped the developers with remediation strategies. Assessing further packages is planned.
Information on their work is available from the University of Wisconsin Vulnerability Assessment page
Other information
More information will be added later.
See also EGEE/GridPP information at: