摘要
在进行风险评估过程中,脆弱性检测由于其检测过程客观、方法多样,已经成为风险评估中必不可少的一个环节。但由于脆弱性检测工具存在各种误报和漏报,大大影响了检测结果的准确性,并进而影响风险评估的有效性。通过对脆弱性检测工具的测试和深入研究,比较了多款典型脆弱性检测工具之间对不同目标系统的检测结果,分析得出了典型脆弱性检测工具之间检测结果的趋势和特点。
The vulnerability scanning for its objectivity and diversity, has become the key part of the risk assessment. However, the vulnerability scanning tools had all kinds of false-alarm and mis-alarm, thus seriously affecting the accuracy of the vulnerability report, even affect the effectiveness of the risk assessment report. Through the test and study of the vulnerability scanning tools, this paper compares several vulnerability scanning tools on the different target operation systems, and concludes the trend of the vulnerability scanning results.
出处
《通信技术》
2009年第4期151-153,共3页
Communications Technology
基金
广州市教育局科技计划(08C068)