A Framework For Classification Software Security Using Common Vulnerabilities And Exposures

The main research aim is to investigate what information is necessary to make a formal vulnerability pattern representation.This is done through the usage of formal Backus-Naur-Form syntax for the execution and presented with newly created vulnerability flow diagram.Some future works were also propo...

Full description

Saved in:
Bibliographic Details
Main Author: Hassan, Nor Hafeizah
Format: Thesis
Language:English
English
Published: 2018
Subjects:
Online Access:http://eprints.utem.edu.my/id/eprint/23353/1/A%20Framework%20For%20Classification%20Software%20Security%20Using%20Common%20Vulnerrabilities%20And%20Exposures.pdf
http://eprints.utem.edu.my/id/eprint/23353/2/A%20Framework%20For%20Classification%20Software%20Security%20Using%20Common%20Vulnerabilities%20And%20Exposures.pdf
http://eprints.utem.edu.my/id/eprint/23353/
http://plh.utem.edu.my/cgi-bin/koha/opac-detail.pl?biblionumber=113299
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: Universiti Teknikal Malaysia Melaka
Language: English
English
id my.utem.eprints.23353
record_format eprints
spelling my.utem.eprints.233532022-02-03T10:34:17Z http://eprints.utem.edu.my/id/eprint/23353/ A Framework For Classification Software Security Using Common Vulnerabilities And Exposures Hassan, Nor Hafeizah Q Science (General) QA76 Computer software The main research aim is to investigate what information is necessary to make a formal vulnerability pattern representation.This is done through the usage of formal Backus-Naur-Form syntax for the execution and presented with newly created vulnerability flow diagram.Some future works were also proposed to further enhance the elements in the secured soft-ware process framework.This thesis focuses on the research and development of the design, formalization and translation of the vulnerability classification pattern through a framework using common vulnerabilities and exposures data.To achieve this aim, the following work was carried out.First step is to create and conceptualized necessary meta-process.Second step is to specify the relationship between the classifiers and vulnerability classification pat-terns. This inclusive of the investigation of vulnerability classification objectives,processes,classifiers and focus domains among prominent framework.Final step is to construct the framework by establishing the formal presentation of the vulnerability classification algo-rithm.The validation process was conducted empirically using statistical method to assess the accuracy and consistency by using the precision and recall rate of the algorithm on five data sets each with 500 samples.The findings show a significant result with precision's error rate or p value is between 0.01 and 0.02 with error rate for recall's error rate is between 0.02 and 0.04.Another validation was conducted to verify the correctness of the classification by using expert opinions,and the results showed that the ambiguity of several cases were subdue. Formal-based classification framework with notation may increase accuracy and vi-sualization compared with hierarchy-tree only,but the conclusion remains tentative because of methodological limitation in the studies. 2018 Thesis NonPeerReviewed text en http://eprints.utem.edu.my/id/eprint/23353/1/A%20Framework%20For%20Classification%20Software%20Security%20Using%20Common%20Vulnerrabilities%20And%20Exposures.pdf text en http://eprints.utem.edu.my/id/eprint/23353/2/A%20Framework%20For%20Classification%20Software%20Security%20Using%20Common%20Vulnerabilities%20And%20Exposures.pdf Hassan, Nor Hafeizah (2018) A Framework For Classification Software Security Using Common Vulnerabilities And Exposures. Doctoral thesis, UTeM. http://plh.utem.edu.my/cgi-bin/koha/opac-detail.pl?biblionumber=113299
institution Universiti Teknikal Malaysia Melaka
building UTEM Library
collection Institutional Repository
continent Asia
country Malaysia
content_provider Universiti Teknikal Malaysia Melaka
content_source UTEM Institutional Repository
url_provider http://eprints.utem.edu.my/
language English
English
topic Q Science (General)
QA76 Computer software
spellingShingle Q Science (General)
QA76 Computer software
Hassan, Nor Hafeizah
A Framework For Classification Software Security Using Common Vulnerabilities And Exposures
description The main research aim is to investigate what information is necessary to make a formal vulnerability pattern representation.This is done through the usage of formal Backus-Naur-Form syntax for the execution and presented with newly created vulnerability flow diagram.Some future works were also proposed to further enhance the elements in the secured soft-ware process framework.This thesis focuses on the research and development of the design, formalization and translation of the vulnerability classification pattern through a framework using common vulnerabilities and exposures data.To achieve this aim, the following work was carried out.First step is to create and conceptualized necessary meta-process.Second step is to specify the relationship between the classifiers and vulnerability classification pat-terns. This inclusive of the investigation of vulnerability classification objectives,processes,classifiers and focus domains among prominent framework.Final step is to construct the framework by establishing the formal presentation of the vulnerability classification algo-rithm.The validation process was conducted empirically using statistical method to assess the accuracy and consistency by using the precision and recall rate of the algorithm on five data sets each with 500 samples.The findings show a significant result with precision's error rate or p value is between 0.01 and 0.02 with error rate for recall's error rate is between 0.02 and 0.04.Another validation was conducted to verify the correctness of the classification by using expert opinions,and the results showed that the ambiguity of several cases were subdue. Formal-based classification framework with notation may increase accuracy and vi-sualization compared with hierarchy-tree only,but the conclusion remains tentative because of methodological limitation in the studies.
format Thesis
author Hassan, Nor Hafeizah
author_facet Hassan, Nor Hafeizah
author_sort Hassan, Nor Hafeizah
title A Framework For Classification Software Security Using Common Vulnerabilities And Exposures
title_short A Framework For Classification Software Security Using Common Vulnerabilities And Exposures
title_full A Framework For Classification Software Security Using Common Vulnerabilities And Exposures
title_fullStr A Framework For Classification Software Security Using Common Vulnerabilities And Exposures
title_full_unstemmed A Framework For Classification Software Security Using Common Vulnerabilities And Exposures
title_sort framework for classification software security using common vulnerabilities and exposures
publishDate 2018
url http://eprints.utem.edu.my/id/eprint/23353/1/A%20Framework%20For%20Classification%20Software%20Security%20Using%20Common%20Vulnerrabilities%20And%20Exposures.pdf
http://eprints.utem.edu.my/id/eprint/23353/2/A%20Framework%20For%20Classification%20Software%20Security%20Using%20Common%20Vulnerabilities%20And%20Exposures.pdf
http://eprints.utem.edu.my/id/eprint/23353/
http://plh.utem.edu.my/cgi-bin/koha/opac-detail.pl?biblionumber=113299
_version_ 1724077949637885952