<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//TaxonX//DTD Taxonomic Treatment Publishing DTD v0 20100105//EN" "../../nlm/tax-treatment-NS0.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:tp="http://www.plazi.org/taxpub" article-type="research-article" dtd-version="3.0" xml:lang="en">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">109</journal-id>
      <journal-id journal-id-type="index">urn:lsid:arphahub.com:pub:3dc5f44e-8666-58db-bc76-a455210e8891</journal-id>
      <journal-title-group>
        <journal-title xml:lang="en">JUCS - Journal of Universal Computer Science</journal-title>
        <abbrev-journal-title xml:lang="en">jucs</abbrev-journal-title>
      </journal-title-group>
      <issn pub-type="ppub">0948-695X</issn>
      <issn pub-type="epub">0948-6968</issn>
      <publisher>
        <publisher-name>Journal of Universal Computer Science</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.3217/jucs-025-09-1043</article-id>
      <article-id pub-id-type="publisher-id">22645</article-id>
      <article-categories>
        <subj-group subj-group-type="heading">
          <subject>Research Article</subject>
        </subj-group>
        <subj-group subj-group-type="scientific_subject">
          <subject>H.3.1 - Content Analysis and Indexing</subject>
          <subject>H.3.2 - Information Storage</subject>
          <subject>H.3.3 - Information Search and Retrieval</subject>
          <subject>H.3.7 - Digital Libraries</subject>
          <subject>H.5.1 - Multimedia Information Systems</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>Determination of System Weaknesses Based on the Analysis of Vulnerability Indexes and the Source Code of Exploits</article-title>
      </title-group>
      <contrib-group content-type="authors">
        <contrib contrib-type="author" corresp="yes">
          <name name-style="western">
            <surname>Fedorchenko</surname>
            <given-names>Andrey</given-names>
          </name>
          <email xlink:type="simple">fedorchenko@comsec.spb.ru</email>
          <xref ref-type="aff" rid="A1">1</xref>
        </contrib>
        <contrib contrib-type="author" corresp="no">
          <name name-style="western">
            <surname>Doynikova</surname>
            <given-names>Elena</given-names>
          </name>
          <xref ref-type="aff" rid="A1">1</xref>
        </contrib>
        <contrib contrib-type="author" corresp="no">
          <name name-style="western">
            <surname>Kotenko</surname>
            <given-names>Igor</given-names>
          </name>
          <xref ref-type="aff" rid="A1">1</xref>
        </contrib>
      </contrib-group>
      <aff id="A1">
        <label>1</label>
        <addr-line content-type="verbatim">St. Petersburg Institute for Informatics and Automation of the Russian Academy of Sciences, St. Petersburg, Russia</addr-line>
        <institution>St. Petersburg Institute for Informatics and Automation of the Russian Academy of Sciences</institution>
        <addr-line content-type="city">St. Petersburg</addr-line>
        <country>Russia</country>
      </aff>
      <author-notes>
        <fn fn-type="corresp">
          <p>Corresponding author: Andrey Fedorchenko (<email xlink:type="simple">fedorchenko@comsec.spb.ru</email>).</p>
        </fn>
        <fn fn-type="edited-by">
          <p>Academic editor: </p>
        </fn>
      </author-notes>
      <pub-date pub-type="collection">
        <year>2019</year>
      </pub-date>
      <pub-date pub-type="epub">
        <day>28</day>
        <month>09</month>
        <year>2019</year>
      </pub-date>
      <volume>25</volume>
      <issue>9</issue>
      <fpage>1043</fpage>
      <lpage>1065</lpage>
      <uri content-type="arpha" xlink:href="http://openbiodiv.net/D1D5983B-55DB-5F20-B3E3-F54DFE3AD0D7">D1D5983B-55DB-5F20-B3E3-F54DFE3AD0D7</uri>
      <uri content-type="zenodo_dep_id" xlink:href="https://zenodo.org/record/4840882">4840882</uri>
      <history>
        <date date-type="received">
          <day>16</day>
          <month>01</month>
          <year>2019</year>
        </date>
        <date date-type="accepted">
          <day>09</day>
          <month>07</month>
          <year>2019</year>
        </date>
      </history>
      <permissions>
        <copyright-statement>Andrey Fedorchenko, Elena Doynikova, Igor Kotenko</copyright-statement>
        <license license-type="creative-commons-attribution" xlink:href="" xlink:type="simple">
          <license-p>This article is freely available under the J.UCS Open Content License.</license-p>
        </license>
      </permissions>
      <abstract>
        <label>Abstract</label>
        <p>Currently the problem of monitoring the security of information systems is highly relevant. One of the important security monitoring tasks is to automate the process of determination of the system weaknesses for their further elimination. The paper considers the techniques for analysis of vulnerability indexes and exploit source code, as well as their subsequent classification. The suggested approach uses open security sources and incorporates two techniques, depending on the available security data. The first technique is based on the analysis of publicly available vulnerability indexes of the Common Vulnerability Scoring System for vulnerability classification by weaknesses. The second one complements the first one in case if there are exploits but there are no associated vulnerabilities and therefore the indexes for classification are absent. It is based on the analysis of the exploit source code for the features, i.e. indexes, using graph models. The extracted indexes are further used for weakness determination using the first technique. The paper provides the experiments demonstrating an effectiveness and potential of the developed techniques. The obtained results and the methods for their enhancement are discussed.</p>
      </abstract>
    </article-meta>
  </front>
</article>
