面向敏感信息检测的Web 综合漏洞扫描器实现  被引量:1

Implementation of Web Comprehensive Vulnerability Scanner for Sensitive Information Detection

在线阅读下载全文

作  者:吕宝路 梁景普 欧翰琪 陈涛 LV Bao-lu;LIANG Jing-pu;OU Han-qi;CHEN Tao(Hunan Agricultural University,Changsha 410000,China;Orient Science&Technology College of Hunan Agricultural Univer-sity,Changsha 410000,China)

机构地区:[1]湖南农业大学,湖南长沙410128 [2]湖南农业大学东方科技学院,湖南长沙410128

出  处:《电脑知识与技术》2020年第23期30-32,共3页Computer Knowledge and Technology

摘  要:互联网的开放性和自由性使得黑客更容易获取到敏感信息,造成网络安全问题的发生。企业通常利用Web扫描器实现安全评估检测,但是这些传统扫描器检测重点为常见安全漏洞类型,如SQL注入、XSS攻击、文件上传等,对于敏感信息的检测程度不足。为此,该文将以传统Web安全扫描器为基础,以加强检测企业敏感信息为目的,采用主机存活判断、端口扫描、指纹识别和漏洞扫描技术实现面向敏感信息检测的Web综合漏洞扫描器,用于扫描易于暴露的敏感信息及网站中可能存在的安全漏洞。同时实现了最新漏洞消息推送功能,最终生成安全报告供开发人员修复使用,有效保障Web应用的安全性。The openness and freedom of the Internet make it easier for hackers to obtain sensitive information and cause network se⁃curity problems.Enterprises usually use web scanners to implement security assessment detection,but these traditional scanners focus on common types of security vulnerabilities,such as SQL injection,XSS attack,file upload,etc.,which are not enough for sen⁃sitive information detection.Therefore,based on the traditional web security scanner,aiming at strengthening the detection of enter⁃prise sensitive information,this paper uses host survival judgment,port scanning,fingerprint identification and vulnerability scan⁃ning technology to realize the web comprehensive vulnerability scanner for sensitive information detection,which is used to scan sensitive information that is easy to be exposed and the possible security vulnerabilities in the website.At the same time,it realizes the latest vulnerability message push function,and finally generates a security report for developers to repair and use,which effec⁃tively guarantees the security of web applications.

关 键 词:敏感信息泄露 漏洞扫描 python扫描器 漏洞推送 安全工具 

分 类 号:TP399[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象