发明申请
- 专利标题: AUTOMATIC CLASSIFICATION OF SECURITY VULNERABILITIES IN COMPUTER SOFTWARE APPLICATIONS
- 专利标题(中): 计算机软件应用中安全漏洞的自动分类
-
申请号: US13609320申请日: 2012-09-11
-
公开(公告)号: US20140075560A1公开(公告)日: 2014-03-13
- 发明人: LOTEM GUY , DANIEL KALMAN , OMER TRIPP , OMRI WEISMAN
- 申请人: LOTEM GUY , DANIEL KALMAN , OMER TRIPP , OMRI WEISMAN
- 申请人地址: US NY ARMONK
- 专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人地址: US NY ARMONK
- 主分类号: G06F21/00
- IPC分类号: G06F21/00
摘要:
Automatically classifying security vulnerabilities in computer software applications by identifying candidate security vulnerabilities in a learning set including at least a first computer software application, classifying each of the candidate security vulnerabilities using predefined classifications, determining, for each of the candidate security vulnerabilities, values for predefined properties, creating a set of correlations between the property values and the classifications of the candidate security vulnerabilities, identifying a candidate security vulnerability in a second computer software application, determining, for the candidate security vulnerability in the second computer software application, values for the predefined properties, and using the set of correlations to classify the candidate security vulnerability in the second computer software application with a classification from the predefined classifications that best correlates with the property values of the candidate security vulnerability in the second computer software application.
公开/授权文献
信息查询