首页> 外国专利> AUTOMATIC ANALYIZING SYSTEM AND METHOD OF SECURITY WEEKNESS OF APPLICATION

AUTOMATIC ANALYIZING SYSTEM AND METHOD OF SECURITY WEEKNESS OF APPLICATION

机译:应用安全弱点自动分析系统及方法

摘要

The present invention relates to an automatic application security vulnerability analysis system, and more specifically, a vulnerability analysis server for automatically performing static analysis and dynamic analysis of an analysis target application to produce a security vulnerability analysis resu And an analysis terminal connected to the vulnerability analysis server and installing and executing the analysis target application. In addition, the present invention relates to an automatic method for analyzing application security vulnerabilities, more specifically, the vulnerability analysis server, (1) installing the analysis target application in the analysis terminal; (2) executing an analysis target application installed in the analysis terminal; (3) automatically attempting an attack on the analysis target application, and monitoring a response to the attack; And (4) automatically analyzing the monitoring result for the attack, and providing a security vulnerability analysis result. According to the proposed system and method for automatically analyzing the security vulnerability of the application proposed by the present invention, by including a vulnerability analysis server for automatically performing static and dynamic analysis of the analysis target application and an analysis terminal for installing and executing the analysis target application, The result of the vulnerability analysis can be quickly obtained through automated analysis, and multiple analysis terminals can be connected to the vulnerability analysis server to automatically analyze multiple applications at the same time. Can be. In addition, according to the present invention, by selecting and standardizing the items required for security vulnerability analysis, and automatically check and analyze the analysis target application for the standardized items, it is possible to obtain a consistent analysis results and improve the analysis reliability Can be. In addition, according to the present invention, by further including a web server, the client can facilitate the security vulnerability analysis request and analysis result confirmation through the web server.
机译:本发明涉及一种自动应用程序安全漏洞分析系统,尤其涉及一种漏洞分析服务器,用于自动对分析目标应用进行静态分析和动态分析,以产生安全漏洞分析结果。分析终端连接到漏洞分析服务器并安装并执行分析目标应用程序。另外,本发明涉及一种用于分析应用程序安全漏洞的自动方法,更具体地,涉及一种漏洞分析服务器,(1)在分析终端中安装分析目标应用程序; (2)执行分析终端中安装的分析目标应用程序; (3)自动对分析目标应用程序发起攻击,并监视对该攻击的响应; (4)自动分析攻击的监控结果,并提供安全漏洞分析结果。根据提出的用于自动分析本发明提出的应用程序的安全漏洞的系统和方法,通过包括用于自动执行分析目标应用程序的静态和动态分析的漏洞分析服务器以及用于安装和执行分析的分析终端目标应用程序,可以通过自动分析快速获得漏洞分析的结果,并且可以将多个分析终端连接到漏洞分析服务器,以同时自动分析多个应用程序。可。另外,根据本发明,通过选择和标准化安全漏洞分析所需的项目,并自动检查和分析标准化项目的分析目标应用程序,可以获得一致的分析结果并提高分析可靠性。是。另外,根据本发明,通过进一步包括网络服务器,客户端可以通过网络服务器促进安全漏洞分析请求和分析结果确认。

著录项

  • 公开/公告号KR102054768B1

    专利类型

  • 公开/公告日2019-12-12

    原文格式PDF

  • 申请/专利权人 주식회사 엔에스에이치씨;

    申请/专利号KR20170159336

  • 发明设计人 최윤영;정원준;

    申请日2017-11-27

  • 分类号G06F21/57;G06F21/56;

  • 国家 KR

  • 入库时间 2022-08-21 11:08:18

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号