Previous Articles     Next Articles

Research on Matching Vulnerabilities and Exploitations based on Open Ports and References

ZHANG Chi%LUO Sen-lin   

  • About author:北京理工大学信息系统及安全对抗实验中心,北京,100081

Abstract: Penetration test is an effective security testing method. One of the key questions in automated penetration testing is to match discovered vulnerabilities and exploitations. Two matching methods based on open ports and references are put forward in this paper. One method is to compare the port numbers of system vulnerabilities with those described in exploitations. The other one is to compare the references of vulnerabilities with those in exploitations. The experimental results show that the recall ratios of the two methods reach 96.8%and 90.3%. Both of the two methods are effective. Furthermore, they can be applied to the penetration test in practical.