Towards Automated Vulnerability Scanning Of Network Servers

PROCEEDINGS OF THE 11TH EUROPEAN WORKSHOP ON SYSTEMS SECURITY (EUROSEC 2018)(2018)

引用 20|浏览78
暂无评分
摘要
We explore a new technique for safe patch fingerprinting to automate vulnerability scanning of network servers. Our technique helps automate the discovery of inputs that safely discriminate vulnerable from patched servers for the latest vulnerabilities. This enables rapid updates to vulnerability scanning tools as new software vulnerabilities are discovered, allowing administrators to scan and secure their networks more quickly. To ensure such scans are safe and ethical, we need to reject inputs with malicious side effects.We have implemented a framework, based on delta execution, which tests the discriminative property of such inputs, as well as their safety. We use a fuzzer to find promising candidate inputs to further automate the process. To illustrate the potential of this approach, we present a Heartbleed case study.
更多
查看译文
关键词
Vulnerability fingerprinting, Internet-wide scanning, Network security
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要