首页> 外文会议>Intelligence and Security Informatics; Lecture Notes in Computer Science; 4430 >Security Assessment for Application Network Services Using Fault Injection
【24h】

Security Assessment for Application Network Services Using Fault Injection

机译:使用故障注入的应用程序网络服务的安全性评估

获取原文
获取原文并翻译 | 示例

摘要

Vulnerabilities in network protocol software have been problematic since Internet infrastructure was deployed. These vulnerabilities damage the reliability of network software and create security holes in computing environment. Many critical security vulnerabilities exist in application network services of which specification or description has not been published. In this paper, we propose a security assessment methodology based on fault injection techniques to improve reliability of the application network services with no specifications published. We also implement a tool for security testing based on the proposed methodology. Windows RPC network services are chosen as an application network service considering its unknown protocol specification and are validated by the methodology. It turns out that the tool detects unknown vulnerabilities in Windows network module.
机译:自部署Internet基础结构以来,网络协议软件中的漏洞就一直存在问题。这些漏洞会破坏网络软件的可靠性,并在计算环境中造成安全漏洞。在尚未发布其规范或描述的应用程序网络服务中存在许多关键的安全漏洞。在本文中,我们提出了一种基于故障注入技术的安全评估方法,以提高应用网络服务的可靠性,但未发布任何规范。我们还基于提出的方法实施了一种用于安全测试的工具。考虑到Windows RPC网络服务的协议规范未知,将其选择为应用程序网络服务,并通过该方法进行验证。事实证明,该工具检测到Windows网络模块中的未知漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号