首页 | 本学科首页   官方微博 | 高级检索  
     

基于攻击图的渗透测试方案自动生成方法
引用本文:崔颖,章丽娟,吴灏. 基于攻击图的渗透测试方案自动生成方法[J]. 计算机应用, 2010, 30(8): 2146-2150
作者姓名:崔颖  章丽娟  吴灏
作者单位:1. 解放军信息工程大学信息工程学院2.
摘    要:为满足网络安全管理需要,提出一种新的渗透测试方案自动生成方法。该方法利用被测试目标网络脆弱点间的逻辑关系,结合原子攻击知识库,通过前向广度优先搜索策略产生渗透攻击图,然后深度优先遍历渗透攻击图生成渗透测试方案,并基于该方法设计实现渗透测试预案自动生成原型系统。实例表明该方法能够有效生成可行的渗透测试方案。

关 键 词:渗透测试  攻击图  原子攻击  攻击推理  网络安全  
收稿时间:2010-01-14
修稿时间:2010-03-03

Automatic generation method for penetration test programs based on attack graph
CUI Ying,ZHANG Li-juan,WU Hao. Automatic generation method for penetration test programs based on attack graph[J]. Journal of Computer Applications, 2010, 30(8): 2146-2150
Authors:CUI Ying  ZHANG Li-juan  WU Hao
Abstract:In order to fulfil the need for network security management, a new automatic generation method of penetration test programs was proposed in this paper. The penetration attack graph was set up with the inference relation of the vulnerabilities in the target network through the forward breadth-first search strategy which combined knowledge of atomic attack. The system produced penetration test programs through reverse depth-first traversal attack graph. A prototype of penetration test programs automatic generating system was designed and implemented on the basis of this method. The illustration indicates that this method can effectively set up the penetration test programs which provide a useful reference for network security analysis.
Keywords:penetration testing   attack graph   atomic attack   attack reasoning   network security
本文献已被 万方数据 等数据库收录!
点击此处可从《计算机应用》浏览原始摘要信息
点击此处可从《计算机应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号