摘要
针对不同厂商安全软件之间的信息表示格式差异带来的软件联动问题,以及一个网络内通常存在多种平台主机的现状,提出一种"管理者/代理"架构的、兼容OVAL的多平台VAS(弱点评估系统)。系统以OVAL作为弱点评估标准,以轻量级Web server为通讯手段,支持多平台主机弱点评估,在保证评估高精度的同时,支持与OVAL兼容的其他安全软件共享安全数据,具有更高的评估完备性和功能扩展性。
Aiming at the flaws of current interoperability problem brought by different information expressing standards between different security products and present situation that a network generally includes several kinds of platforms,a design of manager/ agent architecture-based,OVAL-compatible multi-platform Vulnerability Assessment System(VAS) is given.This system takes OVAL as vulnerability assessment standard and takes lightweight Web server as communicating measure.It supports multi-platform vulnerability assessment and sharing security data with other OVAL-compatible tools with high accuracy,assessing completeness and functional expansibility.
出处
《计算机工程与应用》
CSCD
北大核心
2009年第36期82-85,共4页
Computer Engineering and Applications
基金
国家科技支撑计划项目No.2007BAH08B01
陕西省自然科学基金No.2005f36~~
关键词
联动
多平台
弱点评估系统
开放弱点评估语言
interoperability multi-platform Vulnerability Assessment System(VAS) Open Vulnerability and Assessment Language (OVAL)