Crowdsourcing platform for collaboration management in vulnerability verification

Hung-Jen Su, Jen-Yi Pan
{"title":"Crowdsourcing platform for collaboration management in vulnerability verification","authors":"Hung-Jen Su, Jen-Yi Pan","doi":"10.1109/APNOMS.2016.7737235","DOIUrl":null,"url":null,"abstract":"In recent years, vulnerability collection platforms become an important part to facilitate development of information security. Usually, platform administrators collect and ratify vulnerability information, which white hat hackers report at first hand, and users hence know which applications have doubts via vulnerability reports published on the platform. However, there are still few reported but unverified vulnerabilities, which may be caused from scarcity of testing targets and limitation of man power. These vulnerabilities might agitate those users who have related applications. This study initiates crowdsourcing to vulnerability collection platforms. The proposed platform collaborates administrators with two new added roles, script writers and target providers, aiming at vulnerability verification. In addition we design two agents, the test scheduler and the log collector, to automatically arrange test cases and collect logs, respectively. With properly scoring on task assignment, these crowd sources can effectively and efficiently collaborate on verification of timely and severe vulnerabilities. Hence this platform can speed up the progress of vulnerability assessment in information security.","PeriodicalId":194123,"journal":{"name":"2016 18th Asia-Pacific Network Operations and Management Symposium (APNOMS)","volume":"26 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 18th Asia-Pacific Network Operations and Management Symposium (APNOMS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/APNOMS.2016.7737235","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

Abstract

In recent years, vulnerability collection platforms become an important part to facilitate development of information security. Usually, platform administrators collect and ratify vulnerability information, which white hat hackers report at first hand, and users hence know which applications have doubts via vulnerability reports published on the platform. However, there are still few reported but unverified vulnerabilities, which may be caused from scarcity of testing targets and limitation of man power. These vulnerabilities might agitate those users who have related applications. This study initiates crowdsourcing to vulnerability collection platforms. The proposed platform collaborates administrators with two new added roles, script writers and target providers, aiming at vulnerability verification. In addition we design two agents, the test scheduler and the log collector, to automatically arrange test cases and collect logs, respectively. With properly scoring on task assignment, these crowd sources can effectively and efficiently collaborate on verification of timely and severe vulnerabilities. Hence this platform can speed up the progress of vulnerability assessment in information security.
漏洞验证协同管理的众包平台
近年来,漏洞收集平台成为促进信息安全发展的重要组成部分。通常由平台管理员收集并审核漏洞信息,由白帽黑客第一时间上报,用户通过平台上发布的漏洞报告了解哪些应用存在疑问。然而,报告但未经证实的漏洞仍然很少,这可能是由于测试目标的缺乏和人力的限制造成的。这些漏洞可能会使拥有相关应用程序的用户感到不安。本研究向漏洞收集平台发起众包。提议的平台将管理员与两个新添加的角色——脚本编写者和目标提供者协作,旨在进行漏洞验证。此外,我们还设计了测试调度器和日志收集器两个代理,分别用于自动安排测试用例和收集日志。通过对任务分配进行适当的评分,这些众源可以有效地协作,及时地验证严重的漏洞。因此,该平台可以加快信息安全漏洞评估的进程。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信