首页> 外国专利> TAKING PRIVILEGE ESCALATION INTO ACCOUNT IN PENETRATION TESTING CAMPAIGNS

TAKING PRIVILEGE ESCALATION INTO ACCOUNT IN PENETRATION TESTING CAMPAIGNS

机译:在渗透测试活动中考虑特权升级

摘要

A simulated penetration testing system that assigns network nodes of the tested networked system to classes based on current information about the compromisability of the nodes at a current state of a penetration testing campaign, the classes consisting of (i) a red class for nodes known to be compromisable by the attacker in a way that gives the attacker full control of the nodes, (ii) a blue class for nodes that are not known to be compromisable by the attacker, and (iii) a purple class for nodes known to be compromisable by the attacker in a way that does not give the attacker full control of the purple-class-member network node. The campaign tests whether an attacker would be able to achieve full control of a target node by using privilege escalation techniques and one or more access rights achieved by compromising the target node.
机译:一种模拟渗透测试系统,它基于渗透测试活动当前状态下有关节点的可破坏性的当前信息,将测试网络系统的网络节点分配给类别,这些类别包括(i)已知节点的红色类别能够以使攻击者完全控制节点的方式受到攻击者的破坏,(ii)未知攻击者可以破坏的节点的蓝色类,以及(iii)已知容易受到攻击的节点的紫色类攻击者无法完全控制紫色类成员网络节点。该活动测试攻击者是否能够通过使用特权升级技术以及通过破坏目标节点获得的一个或多个访问权限来实现对目标节点的完全控制。

著录项

  • 公开/公告号WO2020161532A1

    专利类型

  • 公开/公告日2020-08-13

    原文格式PDF

  • 申请/专利权人 XM CYBER LTD.;VAN DYKE MARC;

    申请/专利号WO2019IB54712

  • 发明设计人 LASSER MENAHEM;SEGAL RONEN;

    申请日2019-06-06

  • 分类号H04L29/06;H04L12/26;G06F21/57;

  • 国家 WO

  • 入库时间 2022-08-21 11:09:52

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号