期刊文献+

基于OVAL的安卓漏洞检测评估系统 被引量:2

Android Vulnerability Detection and Assessment System Based on OVAL
下载PDF
导出
摘要 传统漏洞检测工具检测时间长,占用大量系统资源,需要对系统进行模拟攻击,难以应对越来越复杂的安卓漏洞威胁。提出了一种"C/S"架构的、基于开放漏洞评估语言(OVAL)的安卓漏洞检测评估系统。这种架构将大部分评估工作放在控制台端执行,减少了对安卓系统性能的影响,其以OVAL作为漏洞评估标准,在保证评估高精度的同时也具有更好的开放性和可扩展性。 It is difficult to deal with more and more complex security vulnerabilities for the traditional detection tool,which takes a long time,takes up a large number of system resources and needs to simulate the attack.This paper presented a C/S,open vulnerability and assessment language(OVAL)based android vulnerability detection and assessment system.This architecture puts most of the evaluation work to the central control and reduces the impact on the android system performance.Using OVAL as vulnerability assessment standard,the architecture guarantees the high accuracy of the evaluation,and it also has better openness and scalability.
出处 《计算机科学》 CSCD 北大核心 2017年第4期79-81,共3页 Computer Science
关键词 漏洞检测 开放漏洞评估语言 安卓 Vulnerability detection OVAL Android
  • 相关文献

参考文献1

二级参考文献10

  • 1段丹青,陈松乔,杨卫平.漏洞扫描与入侵检测联动系统的研究[J].计算机应用研究,2007,24(7):128-130. 被引量:9
  • 2A complete report of all of the statistics CERT has available cataloged vulnerabilities[EB/OL]. (2007 -04-30 ).http://www.cert.org/stats/ fullstats.html.
  • 3Glossary of terms used in security and intrusion deteetion[EB/OL]. ( 2008-07-20 ).http://www.sans.org/resources/glossary.php.
  • 4An introduction to the OVAL language[EB/OL].(2007-07-11).http://oval.mitre.org/ovaVdocuments/docs-06/an_introduction_to_the_oval_language.pdf.
  • 5CVE-Common Vulnerabilities and Exposures[EB/OL].(2008-07-20). http ://eve.mitre.org.
  • 6An introduction to OVAL compatibility[EB/O L]. ( 2006-07-16 ).http :// oval. mitre.org.
  • 7Network security scanning,patch management vulnerability management[EB/OL].(2008-05-15 ).http://www.gfi.com/lannetscan.
  • 8Red Hat announces OVAL security compatibility[EB/OL].(2008-07- 24 ).http://www.redhat.com/about/news/prarchive/2006/oval mitre.html.
  • 9Martin R A.Transformational vulnerability management through standards[C]//Systems & Software Technology Conference,2005.
  • 10邢栩嘉,林闯,蒋屹新.计算机系统脆弱性评估研究[J].计算机学报,2004,27(1):1-11. 被引量:84

共引文献1

同被引文献7

引证文献2

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部