首页> 外文学位 >Analysis of the automated vulnerability scanning framework: An experimental study.
【24h】

Analysis of the automated vulnerability scanning framework: An experimental study.

机译:自动化漏洞扫描框架分析:一项实验研究。

获取原文
获取原文并翻译 | 示例

摘要

Research has shown that managing information security is one of the top concerns for all business sectors and government sectors. Further, while direct financial loss is not the only threat, digital cyber terrorism is a growing concern and has gained international attention. Therefore, businesses are constantly trying to manage digital security state. In order to manage digital security state, automated vulnerability scanning tools are utilized. Multiple studies have shown that while these tools are great and have matured over last decade, they still have known detection errors. Detection errors include false-positives, false-negatives and DOS (Denial of service). A detection error typically gives a false sense of security and that creates an opportunity for digital attack. Detection errors can be reduced with smart scanning options/algorithms. This study focused on two detection errors: False positives and false negatives. The goal of this study was to understand differences in detection error rates between the original scanning technology and the improved/modified code and procedures. Results from this study demonstrated that the hybrid scanning options/algorithms assisted in reduction of detection errors. Hybrid scanning included dynamic and static scanning algorithms. Further, scanning options/algorithms were designed around configuration vulnerabilities, system vulnerabilities and web application vulnerabilities. Future study can focus on developing hybrid scanning algorithms to better assess security state of digital assets.
机译:研究表明,管理信息安全是所有商业部门和政府部门最关心的问题之一。此外,虽然直接的经济损失不是唯一的威胁,但数字网络恐怖主义却日益引起人们的关注,并引起了国际关注。因此,企业正在不断尝试管理数字安全状态。为了管理数字安全状态,使用了自动漏洞扫描工具。多项研究表明,尽管这些工具很棒,并且在过去十年中已经成熟,但它们仍然具有已知的检测错误。检测错误包括假阳性,假阴性和DOS(拒绝服务)。检测错误通常会给人一种错误的安全感,并为数字攻击创造机会。使用智能扫描选项/算法可以减少检测错误。这项研究的重点是两个检测错误:误报和误报。这项研究的目的是了解原始扫描技术与改进/修改后的代码和过程之间的检测错误率差异。这项研究的结果表明,混合扫描选项/算法有助于减少检测错误。混合扫描包括动态和静态扫描算法。此外,围绕配置漏洞,系统漏洞和Web应用程序漏洞设计了扫描选项/算法。未来的研究将重点放在开发混合扫描算法上,以更好地评估数字资产的安全状态。

著录项

  • 作者

    Patel, Keyur.;

  • 作者单位

    Capella University.;

  • 授予单位 Capella University.;
  • 学科 Computer science.;Information science.;Information Technology.
  • 学位 Ph.D.
  • 年度 2014
  • 页码 96 p.
  • 总页数 96
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号