期刊文献+
共找到2篇文章
< 1 >
每页显示 20 50 100
APU-D* Lite: Attack Planning under Uncertainty Based on D* Lite 被引量:1
1
作者 Tairan Hu Tianyang Zhou +2 位作者 Yichao Zang Qingxian Wang Hang Li 《Computers, Materials & Continua》 SCIE EI 2020年第11期1795-1807,共13页
With serious cybersecurity situations and frequent network attacks,the demands for automated pentests continue to increase,and the key issue lies in attack planning.Considering the limited viewpoint of the attacker,at... With serious cybersecurity situations and frequent network attacks,the demands for automated pentests continue to increase,and the key issue lies in attack planning.Considering the limited viewpoint of the attacker,attack planning under uncertainty is more suitable and practical for pentesting than is the traditional planning approach,but it also poses some challenges.To address the efficiency problem in uncertainty planning,we propose the APU-D*Lite algorithm in this paper.First,the pentest framework is mapped to the planning problem with the Planning Domain Definition Language(PDDL).Next,we develop the pentest information graph to organize network information and assess relevant exploitation actions,which helps to simplify the problem scale.Then,the APU-D*Lite algorithm is introduced based on the idea of incremental heuristic searching.This method plans for both hosts and actions,which meets the requirements of pentesting.With the pentest information graph as the input,the output is an alternating host and action sequence.In experiments,we use the attack success rate to represent the uncertainty level of the environment.The result shows that APU-D*Lite displays better reliability and efficiency than classical planning algorithms at different attack success rates. 展开更多
关键词 Attack planning under uncertainty automated pentest APU-D*Lite algorithm incremental heuristic search
下载PDF
一种基于STIX信息交互的渗透测试协作方案研究 被引量:2
2
作者 刘岳 张海峰 +2 位作者 张良 杨秉杰 边帅 《信息技术与网络安全》 2018年第12期1-5,共5页
对网络安全工作渗透测试工作中的效率瓶颈问题进行了分析,总结了原有测试工作协作方式以及测试过程中的低效之处。对现有威胁情报实时信息共享标准(STIX)进行了介绍,提出了一种基于STIX信息交互的渗透测试协作方案。通过对STIX进行定制... 对网络安全工作渗透测试工作中的效率瓶颈问题进行了分析,总结了原有测试工作协作方式以及测试过程中的低效之处。对现有威胁情报实时信息共享标准(STIX)进行了介绍,提出了一种基于STIX信息交互的渗透测试协作方案。通过对STIX进行定制扩充,可有效提升测试人员与测试人员、测试人员与测试工具以及测试工具之间的信息交互效率,提高信息交互的标准化、自动化程度。 展开更多
关键词 渗透测试 STIX 协作 信息交互 POC
下载PDF
上一页 1 下一页 到第
使用帮助 返回顶部