【24h】

Integrated Exploit Kit for Web Application

机译:用于Web应用程序的集成Exploit套件

获取原文

摘要

In this period, data and information became the most important things to be protected in the organization. Unfortunately, based on SANS 2017 [2], not only small but also large-scale organizations suffered from the incident. That phenomenon happened because of increasing vulnerability, which was not handled carefully. On the other hand, exposed vulnerability increases the risk of assets such as data and information so it needs to be fixed as soon as possible. As a security engineer team in the organization, doing vulnerability identification took time and some time produced many false positives. This paper proposed a solution to decrease false positive in vulnerability identification result and fasten its process by integrating vulnerability identification tool as an exploit kit. In the end, our solution can reduce vulnerability identification time by 50% for two targets and increase vulnerability identification certainty by using manual analysis and proof of concept feature.
机译:在此期间,数据和信息成为组织中最重要的事情。不幸的是,基于2017年的SAN [2],不仅小型,而且还有大型组织遭受这一事件。这种现象发生了因为脆弱性越来越多,没有仔细处理。另一方面,暴露的漏洞增加了资产的风险,例如数据和信息,因此需要尽快修复。作为组织中的安全工程师团队,执行漏洞识别需要时间,一段时间产生了许多误报。本文提出了一种解决方案来减少漏洞识别结果中的假阳性,并通过将漏洞识别工具作为利用套件集成来紧固其过程。最后,我们的解决方案可以通过使用手动分析和概念特征证明来将漏洞识别时间减少50%,并增加漏洞识别确定性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号