Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 800-231

Bug Framework (BF): Formalizing Cybersecurity Weaknesses and Vulnerabilities

Date Published: July 2024

Author(s)

Irena Bojanova (NIST)

Abstract

Keywords

bug classification; bug identification; software/hardware weakness taxonomy; vulnerability detection; safe coding; formal language; specification generation; weakness dataset; vulnerability dataset; vulnerability classification; software bug; firmware bug; hardware defect; hardware logic bug; bug triaging; software error; software fault; software weakness; hardware weakness; software vulnerability; hardware vulnerability; exploit; security failure; secure coding; vulnerability resolution; vulnerability mitigation; labeled dataset; generation tool; graph generation; AI models; formal methods; CVE; CWE; NVD; KEV
Control Families

None selected

Documentation

Publication:
https://doi.org/10.6028/NIST.SP.800-231
Download URL

Supplemental Material:
Bugs Framework project

Document History:
07/30/24: SP 800-231 (Final)

Topics

Security and Privacy

threats

Technologies

software & firmware