发明申请
- 专利标题: Probabilistic mechanism to determine level of security for a software package
- 专利标题(中): 确定软件包安全级别的概率机制
-
申请号: US10870540申请日: 2004-06-17
-
公开(公告)号: US20050283834A1公开(公告)日: 2005-12-22
- 发明人: Kylene Hall , Dustin Kirkland , Emily Ratliff
- 申请人: Kylene Hall , Dustin Kirkland , Emily Ratliff
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 主分类号: G06F11/30
- IPC分类号: G06F11/30 ; G06F12/14 ; H04L9/00 ; H04L9/32
摘要:
A mechanism for determining a probabilistic security score for a software package is provided. The mechanism calculates a raw numerical score that is probabilistically linked to how many security vulnerabilities are present in the source code. The score may then be used to assign a security rating that can be used in either absolute form or comparative form. The mechanism uses a source code analysis tool to determine a number of critical vulnerabilities, a number of serious vulnerabilities, and a number of inconsequential vulnerabilities. The mechanism may then determine a score based on the numbers of vulnerabilities and the number of lines of code.
公开/授权文献
信息查询