Security Basics mailing list archives

How do you use the information in the public Vulnerability Database (NVD, ICAT etc) in application development


From: Rick Zhong <sagiko () gmail com>
Date: Mon, 14 Nov 2005 13:49:44 +0800

Hi,
I am currently working on improving the current public vulnerability
database in terms of the actual utilization of the information. Hope
to get your feedback on how you actually use the information provided
by the public Vulnerability Database (Such as the NVD from NIST , or
icat etc) besides using it as a reference. Do you actually use it in
your applications such as VA scanner, system security checker? If yes
, how do you use it? by parsing the record automatically? use the XML
collection?

If No, what are the hinderance? and what are the aspects which current
public vulnerability databae can be improved so that the information
can be more readily used in application development or other type of
usage. Any feedback is welcomed . Thank you.

regards,
Rick Zhong Liming
www.sinfosec.org
www.security.org.sg


Current thread: