Toward Formalization of Software Security Issues

3 Jul 2023, 16:30
15m
MLIT Conference Hall

MLIT Conference Hall

Distributed Computing Systems Distributed Computing Systems

Speaker

Vladimir Dimitrov (University of Sofia)

Description

CVE, CWE, and CAPEC databases and their relationships are shortly introduced. Focus on this paper is on formalization and more specific on weakness formaliza-tion. Software weaknesses are described as formatted text. There is no widely ac-cepted formal notation for weakness specification. This paper shows how Z-notation can be used for formal specification of CWE-119.

Primary author

Vladimir Dimitrov (University of Sofia)

Presentation materials