Software Vulnerability Severity Classification

Thomas Biege <[email protected]> Wed, 26 Jan 2005 10:05:09 +0100
Newsgroups gmane.comp.security.programming
Message-ID <[email protected]>
Hello,
some time ago I wrote a draft paper about a vulnerability classification
mechanism. It can be used to define the severity of security bugs in
(unix-like) software. 

http://www.suse.de/~thomas/papers/Severity-Metric.pdf

Comments and improvements are very welcome.

Bye,
     Thomas
-- 
 Thomas Biege <[email protected]>, SUSE LINUX AG, Security Support & Auditing
-- 
                  Imagine there's no countries, It isnt hard to do,
                  Nothing to kill or die for, No religion too, ...
                                -- John Lennon (Imagine Lyrics)