A taxonomy of computer program security flaws
- 1 September 1994
- journal article
- Published by Association for Computing Machinery (ACM) in ACM Computing Surveys
- Vol. 26 (3) , 211-254
- https://doi.org/10.1145/185403.185412
Abstract
An organized record of actual flaws can be useful to computer system designers, programmers, analysts, administrators, and users. This survey provides a taxonomy for computer program security flaws, with an Appendix that documents 50 actual security flaws. These flaws have all been described previously in the open literature, but in widely separated places. For those new to the field of computer security, they provide a good introduction to the characteristics of security flaws and how they can arise. Because these flaws were not randomly selected from a valid statistical sample of such flaws, we make no strong claims concerning the likely distribution of actual security flaws within the taxonomy. However, this method of organizing security flaw data can help those who have custody of more representative samples to organize them and to focus their efforts to remove and, eventually, to prevent the introduction of security flaws.Keywords
This publication has 11 references indexed in Scilit:
- Software Quality Measurement: A Framework for Counting Problems and DefectsPublished by Defense Technical Information Center (DTIC) ,1992
- Orthogonal defect classification-a concept for in-process measurementsIEEE Transactions on Software Engineering, 1992
- A Pathology of Computer VirusesPublished by Springer Nature ,1992
- Crisis and aftermathCommunications of the ACM, 1989
- With microscope and tweezers: the worm from MIT's perspectiveCommunications of the ACM, 1989
- The Best Available Technologies for Computer SecurityComputer, 1983
- The “worm” programs—early experience with a distributed computationCommunications of the ACM, 1982
- Formal Models for Computer SecurityACM Computing Surveys, 1981
- Security analysis and enhancements of computer operating systemsPublished by National Institute of Standards and Technology (NIST) ,1976
- A note on the confinement problemCommunications of the ACM, 1973