Automated Reasoning for Vulnerability Management by Design

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Shaked, Avi, Messe, Nan
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913932249137152
author Shaked, Avi
Messe, Nan
author_facet Shaked, Avi
Messe, Nan
contents For securing systems, it is essential to manage their vulnerability posture and design appropriate security controls. Vulnerability management allows to proactively address vulnerabilities by incorporating pertinent security controls into systems designs. Current vulnerability management approaches do not support systematic reasoning about the vulnerability postures of systems designs. To effectively manage vulnerabilities and design security controls, we propose a formally grounded automated reasoning mechanism. We integrate the mechanism into an open-source security design tool and demonstrate its application through an illustrative example driven by real-world challenges. The automated reasoning mechanism allows system designers to identify vulnerabilities that are applicable to a specific system design, explicitly specify vulnerability mitigation options, declare selected controls, and thus systematically manage vulnerability postures.
format Preprint
id arxiv_https___arxiv_org_abs_2507_05794
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Automated Reasoning for Vulnerability Management by Design
Shaked, Avi
Messe, Nan
Cryptography and Security
Artificial Intelligence
Logic in Computer Science
Systems and Control
For securing systems, it is essential to manage their vulnerability posture and design appropriate security controls. Vulnerability management allows to proactively address vulnerabilities by incorporating pertinent security controls into systems designs. Current vulnerability management approaches do not support systematic reasoning about the vulnerability postures of systems designs. To effectively manage vulnerabilities and design security controls, we propose a formally grounded automated reasoning mechanism. We integrate the mechanism into an open-source security design tool and demonstrate its application through an illustrative example driven by real-world challenges. The automated reasoning mechanism allows system designers to identify vulnerabilities that are applicable to a specific system design, explicitly specify vulnerability mitigation options, declare selected controls, and thus systematically manage vulnerability postures.
title Automated Reasoning for Vulnerability Management by Design
topic Cryptography and Security
Artificial Intelligence
Logic in Computer Science
Systems and Control
url https://arxiv.org/abs/2507.05794