期刊文献+

一种新的自学习web应用响应分析算法

A New Algorithm of Self-learning Web Application Response Analysis
下载PDF
导出
摘要 在web应用自动渗透测试技术的发展中,由于在web应用响应分析的自动化与智能化方面的研究不足,现有web应用自动渗透测试中仍然需要人为经验干预,限制了渗透测试的效率,因此,在研究了关键字响应分析技术与被动提取技术的基础上提出了自学习响应分析算法,该算法利用关键字词库对响应结果进行分析,若没有匹配成功再利用启发式分析技术进行分析,当分析结果有效则提取响应的关键字加入词库以达到自学习的目的;实验证明,该算法能够对测试响应结果自动地进行分析,突破了关键字分析技术只能分析含有关键字的响应这一局限,同时,比单纯被动响应提取技术具有更高的效率。 Little research about the analysis of web applications~ s response has been done . Its level of automation and intelligence is very low. And web penetration still requires human intervention which directly limit its efficiency. To solve this problem, key words analy sis and negative response extraction have been studied, and with the help of the two technology a algorithm named self--learnning response analysis is proposed. At first the algorithm use key words to ananlyse the response. If it fails, heuristic analysis technology is used to work it out. The key words extracted from the response will be stored in the database which is used to keep key words. Experimental results show that the algorithm can analyse the response quickly and correctly. And it can analyse the response that key words analysis can not. At the same time, it is more efficient than negative response extraction.
出处 《计算机测量与控制》 2016年第2期251-254,共4页 Computer Measurement &Control
基金 国家自然科学基金项目(61303230) 四川省科技支撑计划项目(11ZS2010)
关键词 WEB应用 响应分析 自学习 web application response analysis self--learning
  • 相关文献

参考文献10

二级参考文献57

  • 1周伟,王丽娜,张焕国.一种基于树结构的网络渗透测试系统[J].计算机与数字工程,2006,34(12):15-18. 被引量:5
  • 2SCAMBRAY J,McCLURE S,KURTZ G.Hacking exposed[M].2nd ed.[S.l.]:Brooks,2001. 被引量:1
  • 3ARCE I,CACERES M.Automating penetration tests:a new challenge for the IS industry[M].[S.l.]:Core Security Tecnologies,2001. 被引量:1
  • 4徐正强.网络信息安全渗透测试平台研究[D].广州:广东工业大学,2008. 被引量:2
  • 5ISECOM.Open-source security testing methodology manual(OSSTMM2.2)[S/OL].(2006-12-13).http://isecom.securenetltd.com/osstmm.en.2.2.pdf. 被引量:1
  • 6German Federal Office for Information Security.A penetration test model[S].German:BSI,2005. 被引量:1
  • 7NIST.Technical guide to information security testing and assessment[S/OL].(2008-09).http://csrc.nist.gov/publications/nistpubs/800-115/SP800-115.pdf. 被引量:1
  • 8The MITRE Corporation.About CPE[EB/OL].(2007-12-19)[2009-03-29].http://cpe.mitre.org/about/index.html. 被引量:1
  • 9The MITRE Corporation.About CVE[EB/OL].(2008-06-04)[2009-03-29].http://cve.mitre.org/about/index.html. 被引量:1
  • 10The MITRE Corporation.About OVAL[EB/OL].(2008-03-06)[2009-04-04].http://oval.mitre.org/oval/about/index.html. 被引量:1

共引文献38

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部