收稿日期: 2010-09-01
修回日期: 2010-11-08
网络出版日期: 2011-09-15
基金资助
国家自然科学基金(60773135,90718007,60970140)资助
Automatic penetration test framework based on unified data format mechanism
Received date: 2010-09-01
Revised date: 2010-11-08
Online published: 2011-09-15
Backtrack4是功能最全面的一款测试平台,但由于数据交换处理机制的缺失使得它难以胜任高效的测试需求.设计了相应的数据格式支持机制,并依此开发了一个渗透测试框架(PTF).该框架会自动使用有关的渗透测试工具进行信息探测、漏洞评估、报告生成.真实网络环境中的实验验证了PTF能高效完成自动化渗透测试,进而大幅提升了使用Backtrack4进行渗透测试的有效性.
关键词: 网络渗透测试; Backtrack4; 自动化; 数据格式支持; PDFL
闻观行 , 张园超 , 张玉清 . 基于数据格式支持机制的自动化渗透测试框架[J]. 中国科学院大学学报, 2011 , 28(5) : 676 -683 . DOI: 10.7523/j.issn.2095-6134.2011.5.016
Backtrack4 is a highly evaluated penetration test platform. It contains large database of security tool collection up-to-date, but it can not work efficiently without data supporting. We propose a penetration test framework (PTF) with unified data format mechanism, which can accomplish penetration testing automatically and efficiently. Tools are used automatically for information detection, vulnerability assessment, and report createment. Real network experiments show that PTF can highly enhance the effectiveness of penetration test using Backtrack4.
[1] Offensive Security. BackTrack Linux . http://www.backtrack-linux.org/.
[2] Fyodor. The art of port scanning . Phrack Magazine, 1997, 7(51): Article 11 .http: //nmap.org/nmap_doc.html.
[3] Deraison R. The nessus attack scripting language reference guide .(2000) http://www.virtualblueness.net/nasl.html.
[4] McNab C. Network security assessment
[M]. O’Reilly Media, 2007.
[5] Kwon O H, Lee S M, Lee H, et al. HackSim: An automation of penetration testing for remote buffer overflow vulnerabilities //Information Networking - Convergence in Broadband and Mobile Networking-International Conference. 2005.
[6] Lee J. Exploit Automation with the Metasploit Framework . BlackHat-DC-2010-Egypt, 2010.
[7] Blyth A. An XML-based architecture to perform data integration and data unification in vulnerability assessments
[J]. Information Security Technical Report, 2003, 8(4):14-25.
[8] Open Information Systems Security Group. ISSAF . . http://www.oissg.org/downloads/issaf/.
[9] Pete Herzog. Open Source security testing methodology manual . . http://www.isecom.org/osstmm/.
[10] InSecure. Nmap data standard . . http://www.insecure.org/nmap/data/nmap.dtd.
[11] Juanma M P. Nessus XMLRPC implementation in Ruby . http://nessus-xmlrpc.rubyforge.org/.
/
| 〈 |
|
〉 |