Software vulnerability assessment: Version extraction and verification

3Citations
Citations of this article
5Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Software vendors do not on a regular basis label their products with the exact software version. This is contrary to branded household products where model numbers and serial numbers allows the consumer to identify the product and get assistance if something goes wrong. We investigated version and product information within 8468 different software programs, where freeware and shareware showed a considerable lack of relevant information. A tool is proposed for identifying relevant version information and for verifying potential threats matched against a software vulnerability database. We suggest that software vendors in the future conform to general conventions of storing version information in a standardized way. © 2007 IEEE.

Cite

CITATION STYLE

APA

Boldt, M., Carlsson, B., & Martinsson, R. (2007). Software vulnerability assessment: Version extraction and verification. In 2nd International Conference on Software Engineering Advances - ICSEA 2007. https://doi.org/10.1109/ICSEA.2007.64

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free