期刊文献+

Google Web安全检测工具研究

Google Web Security Testing Tools-Skipfish Source Code Analysis
下载PDF
导出
摘要 Skipfish是Google2010年推出的一款开源Web安全检测工具,与Nikto和Nessus等工具相比,skipfish使用递归抓取和基于字典的探针技术生成交互式目标网站地图,在性能上采用单线程复用技术、自定义的http堆栈和启发式行为分析等技术减少了网络探测流量,使其具有显著的速度优势。文章针对其源码,重点分析了其使用主要的数据结构、执行流程、多I/O异步机制和字典的使用,对于理解Skipfish软件架构和关键技术并以此为基础进行应用扩展和优化提供了有力的帮助。 Skipfish is an open source web security testing tool launched by Google in 2010.Compared with similar tools such as Nikto and Nessus,Skipfish uses recursive crawl and dictionary-based probe technology to generate an interactive map of the target site.The use of multiplexing single-thread,customized http stack,heuristic behavior analysis and other technologies in performance has reduced the network traffic,and gives Skipfish a significant speed advantage.In this paper,skipfish's source code is analyzed,focusing on its major data structures,the implementation process,multiple I/O asynchronous mechanism and the use of dictionaries.The work is helpful to understand skipfish's software architecture and key technology,and use it as a basis for a special expansion and optimization.
出处 《信息网络安全》 2011年第10期34-37,共4页 Netinfo Security
基金 国家博士后基金(20090451241) 江苏省计算机信息处理技术重点实验室基金(2010)
关键词 GOOGLE Skipfish WEB安全 源码分析 Google Skipfish Web security source code analysis
  • 相关文献

参考文献8

  • 1Arfcle.List of countries by number of Internet users[EB/OL].http://en.wikipedia.org/wiki/List_of_countries_by_number_of_Internet_users,2011-08-30/2011-09-03.
  • 2Markus Jackbsson.黑客新型高级防范.深入剖析犯罪软件[M].北京:人民邮电出版社,2009.388-393.
  • 3Dafydd Stuttard.黑客防范技术宝典.Web实战篇[M].北京:人民邮电出版社,2009.1-8.
  • 4Gilbert Robbins.Top Serious Hacking Attacks This Year 2011[EB/OL].http://www.look4articles.com/Art/213543/190/Top-Serious-Hacking-Attacks-This-Year-2011.html,2011-06-23/2011-09-03.
  • 5skipfish.Crawl results-click to expand[EB/OL] http://www.aldeid.com/wiki/Skipfish,2010-09-19/2011-09-03.
  • 6Skipfrsh.SkipfishDoc Project documentation[EB/OL].http://code.google.com/p/skipfish/wiki/SkipfishDoc,2011-09-03.
  • 7百度空间.如何编译Google提供的SkipFish[EB/OL].http://hi.baidu.com/%B9%F9%B1%FA%D2%E3/blog/item/0786683707a26fdla3cc26ce.html,2010-04-06/201109-03.
  • 8danfom.poll函数简介[EB/OL].http://blog.chinaunix.net/space.php?ui d=439869&do=blog&cuid=2201331,2010-03-24/2011-09-02.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部