Toward Formalization of Software Security Issues
摘要
Abstract
CVE, CWE, and CAPEC databases and their relationships are shortly introduced. Focus on this paper is on formalization and more specific on weakness formalization. Software weaknesses are described as formatted text. There is no widely accepted formal notation for weakness specification. This paper shows how Z-notation can be used for formal specification of CWE-119.