首页> 外文会议>International Conference on Intelligent Computer Communication and Processing >Towards Pentesting Automation Using the Metasploit Framework
【24h】

Towards Pentesting Automation Using the Metasploit Framework

机译:使用Metasploit框架实现自动测试

获取原文

摘要

Penetration testing is a well known methodology assessing security vulnerabilities by executing complex steps which form an attack. Professional pentesting is an expensive service that sometimes cannot fit in the budget of Small and Medium Enterprises. Automating this process means it can be executed even by inexperienced system administrators while it saves time for professionals.The difficulty of this problem consists in the heterogeneity of networks and systems so the techniques need to be adapted each time. Our approach is based on identifying system characteristics, search for existing vulnerabilities and applying machine learning for selecting the most appropriate exploit. The model was trained using data collected from exploited machines on the “Hack the Box” learning platform and delivers exploits from the Metasploit framework.The evaluation shows that the proposed framework can exploit a fair number of systems and can be extended to support new classes of exploits and new pentesting methodologies.
机译:渗透测试是一种众所周知的方法,它通过执行构成攻击的复杂步骤来评估安全漏洞。专业的渗透测试是一项昂贵的服务,有时无法满足中小企业的预算。自动化该过程意味着即使没有经验的系统管理员也可以执行此过程,同时又可以节省专业人员的时间。此问题的困难在于网络和系统的异构性,因此每次都需要对技术进行调整。我们的方法基于识别系统特征,搜索现有漏洞并应用机器学习来选择最合适的漏洞。该模型使用从“ Hack the Box”学习平台上被利用机器收集的数据进行了训练,并提供了Metasploit框架的利用。评估表明,提出的框架可以利用相当数量的系统,并且可以扩展以支持新的类别。漏洞利用和新的渗透测试方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号