![]() |
| Contact Us | Downloads | News October 1, 2008 | Search |
OVAL Working Group on Unauthenticated TestsTeleconference - 7 April 2005Attendees
Minutes compiled by Mike Murray. Meeting SummaryThe second meeting was intended to get the working group back on track. The meeting itself had a relatively small turnout, but key issues were discussed, and next steps were decided upon. Through discussion, three main areas of work have been identified as relevant to the effort:
Through the discussion, those on the call agreed that the first two areas are the key areas, and the solutions to those areas will end up creating the schema. A good deal of the discussion centered on the creation of the metadata for the checks - specifically, about methods for definitions of confidence, accuracy, and invasiveness. Some of this work appears similar to some work that Mike's team had performed internally at nCircle - he committed to posting that work to the Developer list in the near future. In addition, Matt suggested that CVSS may be useful for the definition of some of this metadata. There could be a base confidence level associated with test types, with further Additional categories will likely arise from further discussion on the issue. Raffy brought up the fact that the user may want to tailor some of these values to the environment, again, similar to CVSS. At Matt Wojcik's suggestion, those on the call agreed that working on defining test types should happen first. The committed next steps are to choose a small number of vulnerabilities (5-10) and attempt to develop unauthenticated test types for them. Page Last Updated: February 07, 2008 |
|
||||||||||||