首页> 外文期刊>IEICE transactions on information and systems >A Design of Automated Vulnerability Information Management System for Secure Use of Internet-Connected Devices Based on Internet-Wide Scanning Methods
【24h】

A Design of Automated Vulnerability Information Management System for Secure Use of Internet-Connected Devices Based on Internet-Wide Scanning Methods

机译:自动漏洞信息管理系统的设计,用于基于Internet-ide扫描方法安全使用因特网连接的设备

获取原文
       

摘要

Any Internet-connected device is vulnerable to being hacked and misused. Hackers can find vulnerable IoT devices, infect malicious codes, build massive IoT botnets, and remotely control IoT devices through CC servers. Many studies have been attempted to apply various security features on IoT devices to prevent IoT devices from being exploited by attackers. However, unlike high-performance PCs, IoT devices are lightweight, low-power, and low-cost devices and have limitations on performance of processing and memory, making it difficult to install heavy security functions. Instead of access to applying security functions on IoT devices, Internet-wide scanning (e.g., Shodan) studies have been attempted to quickly discover and take security measures massive IoT devices with weak security. Over the Internet, scanning studies remotely also exist realistic limitations such as low accuracy in analyzing security vulnerabilities due to a lack of device information or filtered by network security devices. In this paper, we propose a system for remotely collecting information from Internet-connected devices and using scanning techniques to identify and manage vulnerability information from IoT devices. The proposed system improves the open-source Zmap engine to solve a realistic problem when attempting to scan through real Internet. As a result, performance measurements show equal or superior results compared to previous Shodan, Zmap-based scanning.
机译:任何互联网连接的设备都容易被攻击和滥用。黑客可以找到漏洞的物联网设备,通过CC服务器传染MARICIAL CODES,BUITICAL CODES和远程控制IOT设备。已经尝试在IOT设备上应用各种安全功能,以防止IOT设备被攻击者利用。但是,与高性能PC不同,IOT设备是重量轻,低功耗和低成本设备,并对处理和内存的性能有局限性,使得难以安装繁忙的安全功能。除了访问IOT设备上的应用安全功能,还尝试使用弱安全性的大规模IOT设备,而不是访问IOT设备上的应用程序扫描(例如,Shodan)研究。通过互联网,由于缺乏设备信息或由网络安全设备过滤,扫描研究也存在诸如分析安全漏洞的低准确性,例如,在分析安全漏洞中的准确性等准确性。在本文中,我们提出了一种用于远程收集来自因特网连接设备的信息,并使用扫描技术来识别和管理来自IoT设备的漏洞信息。建议的系统改进了开源ZMAP引擎,以解决试图扫描真实互联网时的实际问题。结果,与以前的Shodan,ZMAP的扫描相比,性能测量结果显示了相同或更优异的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号