主动Web漏洞扫描中的场景技术研究
收稿日期: 2008-09-15
修回日期: 2008-12-10
网络出版日期: 2010-03-10
Research on the Scenario of the Active Scanning of Web Vulnerability
Received date: 2008-09-15
Revised date: 2008-12-10
Online published: 2010-03-10
余杰 , 李舟军 , 张翀斌 , 李强 . 主动Web漏洞扫描中的场景技术研究[J]. 计算机工程与科学, 2010 , 32(3) : 31 -34 . DOI: 10.3969/j.issn.1007130X.2010.
Recently, Web vulnerability scanning has an important role in network security. However, the most popular open source web vulnerability scanners, such as Nikto, Nessus, etc., have been criticized for their high false alarms, inaccurate evaluation and low sanning efficiency. In this paper, the process of vulnerability scanning is modeled accurately and a new scenariobased scanning strategy is presented. Vulnerability scenario is described by a scenario tree. The algorithms of how to construct and maintain scenario trees in vulnerability databases are also proposed. Finally, we analyze the vulnerability database of Nikto and demonstrate how to construct a scenario tree using its vulnerability records. We prove and validate that the scenariobased scanning strategy can improve the efficiency and veracity of vulnerability sanning.
/
| 〈 |
|
〉 |