Talk With an Expert

Vulnerability naming schemes and description languages: CVE, Bugtraq, AVDL and VulnXML

Vulnerability naming schemes and description languages: CVE, Bugtraq, AVDL and VulnXML (PDF, 1.70MB)Published: 30 May, 2003
Created by
Michael Rohse

Administrators and security experts are usually flooded with attack and vulnerability information, generated by the different security products like Firewalls, Intrusion Detection systems and Vulnerability Assessment tools. To react in a timely manner it is essential that these tools are naming events in a common way. The today's de facto standards CVE (Common Vulnerability Exposures) and the SecurityFocus Bugtraq database will be presented. CVE and Bugtraq have some limitations, they do not describe the vulnerability in enough detail and a common format. These limitations inspired two new proposals: AVDL (Application Vulnerability Description Language) and VulnXML. With them it will be possible to directly import a describing XML document into a scanning tool and the tool will generate and launch the vulnerability scan. AVDL and VulnXML will be described and discussed in this paper.