Computer Engineering & Science >
Research on the Scenario of the Active Scanning of Web Vulnerability
Received date: 2008-09-15
Revised date: 2008-12-10
Online published: 2010-03-10
Recently, Web vulnerability scanning has an important role in network security. However, the most popular open source web vulnerability scanners, such as Nikto, Nessus, etc., have been criticized for their high false alarms, inaccurate evaluation and low sanning efficiency. In this paper, the process of vulnerability scanning is modeled accurately and a new scenariobased scanning strategy is presented. Vulnerability scenario is described by a scenario tree. The algorithms of how to construct and maintain scenario trees in vulnerability databases are also proposed. Finally, we analyze the vulnerability database of Nikto and demonstrate how to construct a scenario tree using its vulnerability records. We prove and validate that the scenariobased scanning strategy can improve the efficiency and veracity of vulnerability sanning.
TU Jie , LI Zhou-Jun , ZHANG Chong-Bin , LI Jiang . Research on the Scenario of the Active Scanning of Web Vulnerability[J]. Computer Engineering & Science, 2010 , 32(3) : 31 -34 . DOI: 10.3969/j.issn.1007130X.2010.
/
| 〈 |
|
〉 |