摘要
如今Web安全已受到企业的极大关注,市面上的自动化Web安全测试工具也层出不穷。由于自动化工具在检测过程中存在漏报现象,故完全信任自动化工具的检测结果往往会造成测试不全面、严重漏洞未检出等情况,给企业带来风险。文章探讨自动化Web安全测试工具漏报情况及其原理,并给出相关的手工测试方案。
Nowadays Web security has been a great concern. We can find varieties of automated Web security testing tools on the market. But automated tools may produce false negatives. If we fully trust the results of automated tools, it will cause an incomprehensive testing or serious vulnerabilities not detected which will bring risks to the organization. This paper discusses the false negative phenomenon and it’s principles of automated Web security testing tools, and gives the method of manual testing.
出处
《信息网络安全》
2013年第1期79-81,共3页
Netinfo Security