Security on Grid computing is often an afterthought. However assessing security of middleware systems is of the utmost importance because they manage critical resources owned by different organizations. To fulfill this objective we use First Principles Vulnerability Assessment (FPVA), an innovative analystic-centric (manual) methodology that goes beyond current automated vulnerability tools. FPVA involves several stages for characterizing the analyzed system and its components. Based on the evaluation of several middleware systems, we have found that there is a gap between the initial and the last stages of FPVA, which is filled with the security practitioner expertise. We claim that this expertise is likely to be systematically codified in order to be able to automatically indicate which, and why, components should be assessed. In this paper we introduce key elements of our approach: Vulnerability graphs, Vulnerability Graph Analyzer, and a Knowledge Base of security configurations.
Publié le : 2012-06-20
Classification:  Grid, middleware, security, vulnerability assessment, vulnerability break graph
@article{cai1483,
     author = {Jairo Serrano; Computer Architecture and Operating System, Universitat Autonoma de Barcelona, 08193 Barcelona and Elisa Heymann; Computer Architecture and Operating System, Universitat Autonoma de Barcelona, 08193 Barcelona and Eduardo Cesar; Computer Architecture and Operating System, Universitat Autonoma de Barcelona, 08193 Barcelona and Barton P. Miller; Computer Sciences Department,. University of Wisconsin, Madison},
     title = {Vulnerability Assessment Enhancement for Middleware for Computing and Informatics},
     journal = {Computing and Informatics},
     volume = {28},
     number = {1},
     year = {2012},
     language = {en},
     url = {http://dml.mathdoc.fr/item/cai1483}
}
Jairo Serrano; Computer Architecture and Operating System, Universitat Autonoma de Barcelona, 08193 Barcelona; Elisa Heymann; Computer Architecture and Operating System, Universitat Autonoma de Barcelona, 08193 Barcelona; Eduardo Cesar; Computer Architecture and Operating System, Universitat Autonoma de Barcelona, 08193 Barcelona; Barton P. Miller; Computer Sciences Department,. University of Wisconsin, Madison. Vulnerability Assessment Enhancement for Middleware for Computing and Informatics. Computing and Informatics, Tome 28 (2012) no. 1, . http://gdmltest.u-ga.fr/item/cai1483/