期刊文献+

基于CVE漏洞库的工控漏洞发现和分析系统研究 被引量:7

Research on Industrial Control Vulnerability Discovery and Analysis System Based on CVE Vulnerability Database
下载PDF
导出
摘要 随着计算机网络技术在工控系统中的应用日益增多,使得工业控制系统被网络中存在的恶意程序或者网络攻击破坏的风险大大增加。因此,如何及时准确地找出工控系统存在的漏洞就显得尤为重要。文章基于CVE工业控制系统漏洞库,借鉴Fuzzing测试、Open VAS等当前主流的漏洞发现技术思想并对其进行改进和提升,设计和开发了工控漏洞发现和分析系统,并搭建工控系统仿真环境对其进行测试,验证了系统的有效性。 As the computer network technology plays a more and more important role in industrial control systems,the risks of destruction from malware or network attacks are greatly increased.Therefore,how to accurately identify the industrial control system vulnerabilities in a timely manner is particularly important.In this paper,Fuzzing test,OpenVAS and other current mainstream discovery techniques are improved and an industrial control vulnerability discovery and analysis system is proposed based on CVE industrial control vulnerabilities library.Simulation results verify the effectiveness of the system.
作者 秦媛媛 朱广宇 田晓娜 陈波 张松清 Qin Yuanyuan;Zhu Guangyu;Tian Xiaona;Chen Bo;Zhang Songqing(The 6th Research Institute of China Electronics Corporation,Beijing 100083,China)
出处 《信息通信技术》 2017年第3期54-59,共6页 Information and communications Technologies
关键词 工控信息安全 漏洞扫描 CVE FUZZING测试 OpenVAS Industrial Information Security Vulnerability Scanning CVE Fuzzing Test OpenVAS
  • 相关文献

参考文献4

二级参考文献33

  • 1Jeff Forristal, Greg Shipley. Vulnerability Assessment Scanners[DB/OL]. Http:∥www. Networkcomputing. Com/1201/1201flb1. Html,2001-01-08.
  • 2Renaud Deraison. Reduce the Costs of an Audit with Nessus 1.2[ DB/OL ]. http:∥www. nessus. com/pres/bh2001/index.html,2001-07-22.
  • 3Fyodor. Remote OS Detection via TCP/IP Stack FingerPrinting[DB/OL]. http:∥www. insecure. org/nmap/nmap-fingerprinting-article. html, 2002-06-11.
  • 4Renaud D,Ron G.A Complete Analysis of Your Security Level[Z].2005.http://www.nessus.org/features/index.php.
  • 5Renaud D.The Nessus Attack Scripting Language Reference Guide[Z].2005-01-03.http://ftp.intevation.de/boss/doc/nasl_guide-20050103.pdf.
  • 6Jay B,Haroon M,Roelof T,et al.Nessus Network Auditing[M].Syngress Publishing,2004.
  • 7Ian Foster.Designing and building parallel programs: concepts & tools for parallel softwareengineering[]..1995
  • 8http://NMAP.org/ .
  • 9TILERA.TILE Architecture-Overview.pdf[]..2008
  • 10TILERA.TILE Programming-Overview.pdf[]..2008

共引文献18

同被引文献43

引证文献7

二级引证文献14

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部