中文

基于黑板架构的系统漏洞分析工具的技术升级与增强

密码学与安全 2024-09-18 v1

摘要

针对无法离线或无法承受传统渗透测试风险的关键任务系统(CMCS),我们先前开发了一种系统漏洞分析技术(SVAT)。该系统使用基于路径的漏洞分析来识别对系统安全的潜在威胁。基于黑板架构的规则-事实范式的泛化逻辑已在该软件中实现,即“软件运行与网络攻击结果审查”(SONARR)。本文概述了该工具新增的功能,以及为分析其有效性和SONARR算法新内存处理能力的性能优势而进行的实验。文中讨论了性能测试结果及其与网络的关系。最后,文章讨论了未来的工作方向,包括实现多线程、增加机密性、完整性和可用性等分析指标,以及改进启发式算法的开发。

关键词

引用

@article{arxiv.2409.10893,
  title  = {Enhancing Security Testing Software for Systems that Cannot be Subjected to the Risks of Penetration Testing Through the Incorporation of Multi-threading and and Other Capabilities},
  author = {Matthew Tassava and Cameron Kolodjski and Jordan Milbrath and Jeremy Straub},
  journal= {arXiv preprint arXiv:2409.10893},
  year   = {2024}
}

备注

The U.S. federal sponsor has requested that we not include funding acknowledgement for this publication