首页> 外文期刊>ETRI journal >PKG-VUL: Security Vulnerability Evaluation and Patch Framework for Package-Based Systems
【24h】

PKG-VUL: Security Vulnerability Evaluation and Patch Framework for Package-Based Systems

机译:PKG-VUL:基于软件包的系统的安全漏洞评估和修补程序框架

获取原文
           

摘要

In information security and network management, attacks based on vulnerabilities have grown in importance. Malicious attackers break into hosts using a variety of techniques. The most common method is to exploit known vulnerabilities. Although patches have long been available for vulnerabilities, system administrators have generally been reluctant to patch their hosts immediately because they perceive the patches to be annoying and complex. To solve these problems, we propose a security vulnerability evaluation and patch framework called PKG-VUL, which evaluates the software installed on hosts to decide whether the hosts are vulnerable and then applies patches to vulnerable hosts. All these operations are accomplished by the widely used simple network management protocol (SNMP). Therefore, system administrators can easily manage their vulnerable hosts through PKG-VUL included in the SNMP-based network management systems as a module. The evaluation results demonstrate the applicability of PKG-VUL and its performance in terms of devised criteria.
机译:在信息安全和网络管理中,基于漏洞的攻击变得越来越重要。恶意攻击者可以使用多种技术来入侵主机。最常见的方法是利用已知漏洞。尽管补丁程序早已可用于漏洞,但系统管理员通常不愿立即修补其主机,因为他们认为修补程序令人讨厌且复杂。为了解决这些问题,我们提出了一个称为PKG-VUL的安全漏洞评估和修补程序框架,该框架将评估主机上安装的软件,以确定主机是否易受攻击,然后将修补程序应用于易受攻击的主机。所有这些操作都是通过广泛使用的简单网络管理协议(SNMP)完成的。因此,系统管理员可以通过基于SNMP的网络管理系统中作为模块的PKG-VUL轻松管理其易受攻击的主机。评估结果证明了PKG-VUL的适用性及其在设计标准方面的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号