【24h】

Penetration testing automation assessment method based on rule tree

机译:基于规则树的渗透测试自动化评估方法

获取原文
获取原文并翻译 | 示例

摘要

With the application to assess the network and system security in some key fields, penetration testing assessment methods have been evolving into a popular research topic. However, the automation degree of penetration testing is at a lower level, and many parameters of security assessment method is uncertain. For these two problems above, we use rule trees method to achieve the automation process of penetration testing, and each chain of rule trees stores a complete the attack process. By using the result of penetration testing, we propose the security assessment process to meet the NIST guidelines, and it can make some uncertain parameters of security assessment clear. With the constant expansion of rule trees, the proposed method can improve the accuracy and effectiveness of security assessment.
机译:随着在某些关键领域中评估网络和系统安全性的应用,渗透测试评估方法已经发展成为一个流行的研究主题。但是,渗透测试的自动化程度较低,安全评估方法的许多参数不确定。针对上述两个问题,我们使用规则树方法来实现渗透测试的自动化过程,并且规则树的每个链都存储了完整的攻击过程。通过使用渗透测试的结果,我们提出了符合NIST准则的安全评估过程,它可以使一些不确定的安全评估参数变得清晰。随着规则树的不断扩展,该方法可以提高安全性评估的准确性和有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号