首页> 外文期刊>Information systems frontiers >An OVAL-based active vulnerability assessment system for enterprise computer networks
【24h】

An OVAL-based active vulnerability assessment system for enterprise computer networks

机译:基于OVAL的企业计算机网络主动漏洞评估系统

获取原文
获取原文并翻译 | 示例
           

摘要

Many security problems are caused by vulnerabilities hidden in enterprise computer networks. It is very important for system administrators to have knowledge about the security vulnerabilities. However, current vulnerability assessment methods may encounter the issues of high false positive rates, long computational time, and requirement of developing attack codes. Moreover, they are only capable of locating individual vulnerabilities on a single host without considering correlated effect of these vulnerabilities on a host or a section of network with the vulnerabilities possibly distributed among different hosts. To address these issues, an active vulnerability assessment system NetScope with C/S architecture is developed for evaluating computer network security based on open vulnerability assessment language instead of simulating attacks. The vulnerabilities and known attacks with their prerequisites and consequences are modeled based on predicate logic theory and are correlated so as to automatically construct potential attack paths with strong operation power of relational database management system. The testing results from a series of experiments show that this system has the advantages of a low false positive rate, short running periods, and little impact on the performance of audited systems and good scalability. The security vulnerabilities, undetectable if assessed individually in a network, are discovered without the need to simulate attacks. It is shown that the NetScope system is well suited for vulnerability assessment of large-scale computer networks such as campus networks and enterprise networks. Moreover, it can also be easily integrated with other security tools based on relational databases.
机译:许多安全问题是由企业计算机网络中隐藏的漏洞引起的。对于系统管理员来说,了解有关安全漏洞的知识非常重要。但是,当前的漏洞评估方法可能会遇到误报率高,计算时间长以及开发攻击代码的要求。而且,它们仅能够在单个主机上定位单个漏洞,而无需考虑这些漏洞对主机或网络部分的相关影响,而这些漏洞可能分布在不同的主机之间。为了解决这些问题,开发了具有C / S架构的主动漏洞评估系统NetScope,用于基于开放漏洞评估语言而不是模拟攻击来评估计算机网络安全。基于谓词逻辑理论对漏洞和已知攻击及其先决条件和后果进行建模,并进行关联,以自动构建具有强大关系数据库管理系统功能的潜在攻击路径。一系列实验的测试结果表明,该系统具有误报率低,运行周期短,对审计系统的性能影响小,扩展性好等优点。发现安全漏洞(如果在网络中逐个评估则无法检测到),而无需模拟攻击。结果表明,NetScope系统非常适合用于大型计算机网络(如校园网络和企业网络)的漏洞评估。此外,它还可以轻松地与基于关系数据库的其他安全工具集成。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号