Vladimir Dimitrov
(University of Sofia)
CVE, CWE, and CAPEC databases and their relationships are shortly introduced. Focus on this paper is on formalization and more specific on weakness formaliza-tion. Software weaknesses are described as formatted text. There is no widely ac-cepted formal notation for weakness specification. This paper shows how Z-notation can be used for formal specification of CWE-119.
Primary author
Vladimir Dimitrov
(University of Sofia)