期刊文献+

一种有效的Web指纹识别方法 被引量:9

An efficient method of web fingerprint identification
下载PDF
导出
摘要 准确获取Web服务器及其承载的应用的类型及版本对Web站点的安全测试有重要意义.针对Web服务器Banner易被修改,提出使用黑盒测试方法对主流Web服务器进行分析,进而选取可有效防止Banner欺骗的Web服务器指纹;针对Web应用关键字易被删除,提出使用源码审计方法对主流开源Web应用进行分析,进而选取与其功能相关的Web应用指纹,并构建Web指纹库.在此基础上,设计并实现Web指纹识别工具——Web Eye.实验结果表明,与主流工具相比,Web Eye能更快速准确地识别Web服务器及应用,并具有良好的可扩展性. It is very important to accurately acquire information of the web server and deployed application for website security testing. Since the web server' s Banner was apt to be modified, we used the black-box testing method to analyze major web servers, and then selected web server' s fingerprint which could prevent Banner cheating. Since the web application' s keywords were apt to be deleted, we used the source code audit method to analyze major web applications, and then selected web application' s fingerprint, which was associated with its function, and built a web fingerprint database. Furthermore, a web fingerprint identifying tool WebEye was designed and implemented. Experimental results show that WebEye faster and more accurately identifies the web server and application than similar tools, and it has good sealablity.
出处 《中国科学院大学学报(中英文)》 CSCD 北大核心 2016年第5期679-685,共7页 Journal of University of Chinese Academy of Sciences
基金 国家自然科学基金(61572460 61272481) 信息安全国家重点实验室开放课题基金(2015-MS-06) 360项目资助
关键词 WEB服务器 WEB应用 Web指纹识别 Web指纹库 web server web application web fingerprint identification web fingerprint database
  • 相关文献

参考文献16

  • 1ZoomEye.ZoomEye网络空间搜索引擎[EB/OL].[2016-01-201.https://www.zoomeye.org!.
  • 2Watson D. The evolution of web application attacks [ J ]. Network Security, 2007(11 ): 7-12.
  • 3Goethem T V, Chen P, Nikiforakis N, et al. Large-scale security analysis of the web: challenges and findings [ J ]. Lecture Notes in Computer Science, 2014, 8564:110-126.
  • 4Dukes L S, Yuan X, Akowuah F. A case study on web application security testing with tools and manual testing [ C ]//Southeastcon, 2013 Proceedings of IEEE. IEEE, 2013 : 1- 6.
  • 5Lee D, Rowe J, Ko C, et al. Detecting and defending against Web-server fingerprinting [ C ] // Proceedings of Computer Security Applications Conference, 2002. l$th Annual. IEEE, 2002: 321-330.
  • 6Karthik R, Kamath S. W3-Scrape-A windows based reconnaissance tool for web application fingerprinting [ R ]. arXiv : 1306. 6839.
  • 7Fielding R, Gettys J, Mogul J, et al. Hypertext transfer protocol-HTTP/1.1 [ EB/OL ]. ( 1999 ) [ 2016-01-20 ]. http:// www. ffc-base, org/txt/ffc-2616, txt.
  • 8Yang K, Hu L, Zhang N, et al. Improving the Defence against Web Server Fingerprinting by Eliminating Compliance Variation [ C ] // Proceedings of the 2010 Fifth International Conference on Frontier of Computer Science and Technology. IEEE Computer Society, 2010:227-232.
  • 9Huang Z, Xia C, Sun B, et al. Analyzing and summarizing the web server detection technology based on HTTP [ C ]// Software Engineering and Service Science ( ICSESS), 2015 6th IEEE International Conference on. IEEE, 2015:1 042- 1 045.
  • 10Book T, Witick M, Wallach D S. Automated generation of web server fingerprints[ R ]. arXiv: 1305. 0245.

同被引文献37

引证文献9

二级引证文献13

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部