首页|漏洞基准测试集构建技术综述

漏洞基准测试集构建技术综述

扫码查看
随着软件漏洞分析技术的发展,针对不同漏洞的发现技术和工具被广泛使用.但是如何评价不同技术、方法、工具的能力边界是当前该领域未解决的基础性难题.而构建用于能力评估的漏洞基准测试集(Vulnerability Benchmark)是解决该基础性难题的关键.文中梳理了近20年漏洞基准测试集构建的相关代表性成果.首先从自动化的角度阐述了基准测试集的发展历程;然后对基准测试集构建技术进行了分类,给出了基准测试集构建的通用流程模型,并阐述了不同测试集构建方法的思想、流程以及存在的不足;最后总结当前研究的局限性,并对下一步研究进行了展望.
Survey of Vulnerability Benchmark Construction Technique
The development of technology for software vulnerability analysis has led to the widespread use of various techniques and tools for discovering vulnerabilities.Nevertheless,assessing the capability boundary of these techniques,methods,and tools remains a fundamental problem in this field.A vulnerability benchmark for capability assessment plays a pivotal role in solving this problem.The purpose of this paper is to review representative results related to the construction of benchmark test sets over the past 20 years.Firstly,it explains the developmental history of vulnerability benchmark from an automation perspective.Then,it classifies the techniques for constructing vulnerability benchmark and provide a general process model,explaining the ideas and processes of different construction methods and their limitations.Lastly,the limitations of current research are summarized and the future research is prospected.

Vulnerability benchmarkSoftware vulnerability analysisEvaluation metrics

马总帅、武泽慧、燕宸毓、魏强

展开 >

信息工程大学数学工程与先进计算国家重点实验室 郑州 450001

漏洞基准测试集 软件漏洞分析 评估指标

国家重点研发计划

2019QY0501

2024

计算机科学
重庆西南信息有限公司(原科技部西南信息中心)

计算机科学

CSTPCD北大核心
影响因子:0.944
ISSN:1002-137X
年,卷(期):2024.51(1)
  • 1
  • 73