• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊
论文

Research on the Scenario of the Active Scanning of Web Vulnerability

  • TU Jie ,
  • LI Zhou-Jun ,
  • ZHANG Chong-Bin ,
  • LI Jiang
Expand
  • (School of Computer Science,National University of Defense Technology,Changsha 410073)

Received date: 2008-09-15

  Revised date: 2008-12-10

  Online published: 2010-03-10

Abstract

Recently, Web vulnerability scanning has an important role in network security. However, the most popular open source web vulnerability scanners, such as Nikto, Nessus, etc., have been criticized for their high false alarms, inaccurate evaluation and low sanning efficiency. In this paper, the process of vulnerability scanning is modeled accurately and a new scenariobased scanning strategy is presented. Vulnerability scenario is described by a scenario tree. The algorithms of how to construct and maintain scenario trees in vulnerability databases are also proposed. Finally, we analyze the vulnerability database of Nikto and demonstrate how to construct a scenario tree using its vulnerability records. We prove and validate that the scenariobased scanning strategy can improve the efficiency and veracity of vulnerability sanning.

Cite this article

TU Jie , LI Zhou-Jun , ZHANG Chong-Bin , LI Jiang . Research on the Scenario of the Active Scanning of Web Vulnerability[J]. Computer Engineering & Science, 2010 , 32(3) : 31 -34 . DOI: 10.3969/j.issn.1007130X.2010.

Outlines

/