首页> 外国专利> Site independent methods for deriving contextually tailored security vulnerability corrections for hardening solution stacks

Site independent methods for deriving contextually tailored security vulnerability corrections for hardening solution stacks

机译:站点无关的方法,用于根据上下文量身定制安全漏洞更正,以强化解决方案堆栈

摘要

In auditing a target Web site for security exposures, site specific remediation reports are generated to provide instructional data tailored to components of the Web server solution stack as determined by the auditing computer system. Stack and component identification is performed in a site independent manner based on an analysis of Web page data retrieved by the auditing computer system. Informational aspects of the received data are recognized individually and by various patterns evident in the received data, enabling further identification of component implementation aspects, such as revision levels. Based on the informational and implementation aspects, site, solution stack, and component specific security audit tests are executed against the target Web site. Audit identified security exposures are recorded in correspondence with site, solution stack, and component implementation specific remediation instruction data. This audit data is then available for reporting.
机译:在审核目标网站的安全漏洞时,将生成特定于站点的补救报告,以提供针对审核服务器系统确定的Web服务器解决方案堆栈组件的指导性数据。基于对审计计算机系统检索到的网页数据的分析,以与站点无关的方式执行堆栈和组件标识。接收到的数据的信息方面可以通过接收到的数据中明显的各种模式单独识别,从而可以进一步识别组件实现方面,例如修订级别。基于信息和实现方面,针对目标网站执行站点,解决方案堆栈和特定于组件的安全审核测试。审核确定的安全风险与站点,解决方案堆栈以及组件实施特定的补救说明数据相对应地进行记录。然后可以使用此审核数据进行报告。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号