发明名称 System, method and program product to determine security risk of an application
摘要 A system, method and program product for evaluating a security risk of an application. A determination is made whether unauthorized access or loss of data maintained or accessed by the application would cause substantial damage. A determination is made whether the application is shared by different customers. A determination is made whether a vulnerability in the application can be exploited by a person or program which has not been authenticated to the application or a system in which the application runs. A numerical value or weight is assigned to each of the foregoing determinations. Each of the numerical values or weights corresponds to a significance of the determination in evaluating said security risk. The numerical values or weights are combined to evaluate the security risk. Other factors can also be considered in evaluating the security risk.
申请公布号 US2005086530(A1) 申请公布日期 2005.04.21
申请号 US20030690017 申请日期 2003.10.21
申请人 INTERNATIONAL BUSINESS MACHINES CORP. 发明人 GODDARD JAMES P.
分类号 G06F11/30;(IPC1-7):G06F11/30 主分类号 G06F11/30
代理机构 代理人
主权项
地址