欢迎访问中国科学院大学学报,今天是
论文

基于数据格式支持机制的自动化渗透测试框架

  • 闻观行 ,
  • 张园超 ,
  • 张玉清
展开
  • 1. 中国科学院研究生院国家计算机网络入侵防范中心, 北京 100049;
    2. 西安电子科技大学, 西安 710065

收稿日期: 2010-09-01

  修回日期: 2010-11-08

  网络出版日期: 2011-09-15

基金资助

国家自然科学基金(60773135,90718007,60970140)资助 

Automatic penetration test framework based on unified data format mechanism

  • WEN Guan-Xing ,
  • ZHANG Yuan-Chao ,
  • ZHANG Yu-Qing
Expand
  • 1. National Computer Network Intrusion Protection Center, Graduate University, Chinese Academy of Sciences, Beijing 100049, China;
    2. Xi Dian University, Xi’an 710065, China

Received date: 2010-09-01

  Revised date: 2010-11-08

  Online published: 2011-09-15

摘要

Backtrack4是功能最全面的一款测试平台,但由于数据交换处理机制的缺失使得它难以胜任高效的测试需求.设计了相应的数据格式支持机制,并依此开发了一个渗透测试框架(PTF).该框架会自动使用有关的渗透测试工具进行信息探测、漏洞评估、报告生成.真实网络环境中的实验验证了PTF能高效完成自动化渗透测试,进而大幅提升了使用Backtrack4进行渗透测试的有效性.

本文引用格式

闻观行 , 张园超 , 张玉清 . 基于数据格式支持机制的自动化渗透测试框架[J]. 中国科学院大学学报, 2011 , 28(5) : 676 -683 . DOI: 10.7523/j.issn.2095-6134.2011.5.016

Abstract

Backtrack4 is a highly evaluated penetration test platform. It contains large database of security tool collection up-to-date, but it can not work efficiently without data supporting. We propose a penetration test framework (PTF) with unified data format mechanism, which can accomplish penetration testing automatically and efficiently. Tools are used automatically for information detection, vulnerability assessment, and report createment. Real network experiments show that PTF can highly enhance the effectiveness of penetration test using Backtrack4.

参考文献


[1] Offensive Security. BackTrack Linux . http://www.backtrack-linux.org/.

[2] Fyodor. The art of port scanning . Phrack Magazine, 1997, 7(51): Article 11 .http: //nmap.org/nmap_doc.html.

[3] Deraison R. The nessus attack scripting language reference guide .(2000) http://www.virtualblueness.net/nasl.html.

[4] McNab C. Network security assessment
[M]. O’Reilly Media, 2007.

[5] Kwon O H, Lee S M, Lee H, et al. HackSim: An automation of penetration testing for remote buffer overflow vulnerabilities //Information Networking - Convergence in Broadband and Mobile Networking-International Conference. 2005.

[6] Lee J. Exploit Automation with the Metasploit Framework . BlackHat-DC-2010-Egypt, 2010.

[7] Blyth A. An XML-based architecture to perform data integration and data unification in vulnerability assessments
[J]. Information Security Technical Report, 2003, 8(4):14-25.

[8] Open Information Systems Security Group. ISSAF . . http://www.oissg.org/downloads/issaf/.

[9] Pete Herzog. Open Source security testing methodology manual . . http://www.isecom.org/osstmm/.

[10] InSecure. Nmap data standard . . http://www.insecure.org/nmap/data/nmap.dtd.

[11] Juanma M P. Nessus XMLRPC implementation in Ruby . http://nessus-xmlrpc.rubyforge.org/.

文章导航

/