期刊文献+

脆弱性检测工具研究 被引量:2

Study of Vulnerability Scanning Tool
原文传递
导出
摘要 在进行风险评估过程中,脆弱性检测由于其检测过程客观、方法多样,已经成为风险评估中必不可少的一个环节。但由于脆弱性检测工具存在各种误报和漏报,大大影响了检测结果的准确性,并进而影响风险评估的有效性。通过对脆弱性检测工具的测试和深入研究,比较了多款典型脆弱性检测工具之间对不同目标系统的检测结果,分析得出了典型脆弱性检测工具之间检测结果的趋势和特点。 The vulnerability scanning for its objectivity and diversity, has become the key part of the risk assessment. However, the vulnerability scanning tools had all kinds of false-alarm and mis-alarm, thus seriously affecting the accuracy of the vulnerability report, even affect the effectiveness of the risk assessment report. Through the test and study of the vulnerability scanning tools, this paper compares several vulnerability scanning tools on the different target operation systems, and concludes the trend of the vulnerability scanning results.
作者 程晓峰 赵禹
出处 《通信技术》 2009年第4期151-153,共3页 Communications Technology
基金 广州市教育局科技计划(08C068)
关键词 风险评估 脆弱性 脆弱性检测工具 NMAP nessos X-SCAN Risk assessment Vulnerability Vulnerability scanning tools
  • 相关文献

参考文献5

  • 1Robert Richardson CSI 2007 Computer Crime and Security Survey [2008.1].
  • 2http:// www. insecure, org/ [2007.6].
  • 3http://www. nessus, org/ [2007.8]
  • 4http://www. xfocus, net [2007.8].
  • 5Sarah Lord 2007 Guangzhou Information Security Summit CRA International Vice President [2008.4].

同被引文献20

  • 1冯登国,张阳,张玉清.信息安全风险评估综述[J].通信学报,2004,25(7):10-18. 被引量:312
  • 2周权.网络系统安全风险评估研究.计算机科学,2007,34(7):317-319.
  • 3Anita Vorster, Les Labuschagne. A Framework for Different Information Security Risk Comparing Analysis Methodologies[C]//Anita Vorster, Les Labuschagne. Proceedings of the 2005 annual research conference of the South African institute of computer scientists and information technologists on IT research in developing countries. White River, South Africa:South African Institute for Computer Scientists and Information Technologists, [s. l.]:Anita Vorster, 2005: 95-103.
  • 4GB/T20984-2007,信息安全技术信息 系统的风险评估规范[S].
  • 5通用弱点评价体系(CVSS)简介[EB/OL].(2006-02-08)[2009-5-17].http://www.xfocus.net/atticles/200602/850.html.
  • 6于洪珍,徐立忠,王慧斌.监测监控信息融合技术[M].北京:清华大学出版社,2011.
  • 7王馨,刘海砚,季晓林,等.信息融合技术的发展与展望[J].仪器仪表学报,2007,28(4 增刊):175 -179.
  • 8Bass T. Service-Oriented Horizontal Fusion in Distributed Coordination-Based Systems[J]. IEEE MILCOM,2004.
  • 9Salerno J J, Hinman M, Boulware D. A situation awareness model ap-plied to multiple domains [ C] //Proceedings of the Defense and Securi-ty Conference,Orlando,FL,USA,2005 :65 ~74.
  • 10Siaterlis C, Maglaris B. Towards Multisensor Data fusion for DDOS De-tection [ C]//Proc of the 2004 ACM Symp on Applied Computing,2004:439-446.

引证文献2

二级引证文献5

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部