CN107508830B - 一种减少网站漏洞扫描漏报的方法 - Google Patents
一种减少网站漏洞扫描漏报的方法 Download PDFInfo
- Publication number
- CN107508830B CN107508830B CN201710854522.1A CN201710854522A CN107508830B CN 107508830 B CN107508830 B CN 107508830B CN 201710854522 A CN201710854522 A CN 201710854522A CN 107508830 B CN107508830 B CN 107508830B
- Authority
- CN
- China
- Prior art keywords
- vulnerability
- scanning
- website
- result
- database
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000000034 method Methods 0.000 title claims abstract description 10
- 238000012545 processing Methods 0.000 claims description 2
- 238000012795 verification Methods 0.000 claims description 2
- 238000005516 engineering process Methods 0.000 abstract description 7
- 238000004891 communication Methods 0.000 description 2
- 238000001514 detection method Methods 0.000 description 2
- 230000009286 beneficial effect Effects 0.000 description 1
- 238000010276 construction Methods 0.000 description 1
- 230000009193 crawling Effects 0.000 description 1
- 230000007812 deficiency Effects 0.000 description 1
- 238000013461 design Methods 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 238000012360 testing method Methods 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1433—Vulnerability analysis
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer And Data Communications (AREA)
- Storage Device Security (AREA)
Abstract
Description
指纹 | 网站标识 | 策略标识 |
Finger1 | Website1 | Policy1 |
Finger3 | Website1 | Policy1 |
指纹 | 网站标识 | 策略标识 |
Finger1 | Website1 | Policy1 |
Finger2 | Website1 | Policy1 |
Finger3 | Website1 | Policy1 |
指纹 | 网站标识 | 策略标识 |
Finger2 | Website1 | Policy1 |
Claims (2)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201710854522.1A CN107508830B (zh) | 2017-09-20 | 2017-09-20 | 一种减少网站漏洞扫描漏报的方法 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201710854522.1A CN107508830B (zh) | 2017-09-20 | 2017-09-20 | 一种减少网站漏洞扫描漏报的方法 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN107508830A CN107508830A (zh) | 2017-12-22 |
CN107508830B true CN107508830B (zh) | 2019-11-08 |
Family
ID=60698098
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201710854522.1A Active CN107508830B (zh) | 2017-09-20 | 2017-09-20 | 一种减少网站漏洞扫描漏报的方法 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN107508830B (zh) |
Families Citing this family (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN108881284A (zh) * | 2018-07-17 | 2018-11-23 | 深圳市极限网络科技有限公司 | 一种网络空间漏洞归并平台远程攻击控制系统 |
CN110753047B (zh) * | 2019-10-16 | 2022-02-11 | 杭州安恒信息技术股份有限公司 | 一种减少漏洞扫描误报的方法 |
CN111935121B (zh) * | 2020-07-31 | 2022-04-26 | 北京天融信网络安全技术有限公司 | 一种漏洞上报方法及装置 |
CN112632559A (zh) * | 2020-12-24 | 2021-04-09 | 北京天融信网络安全技术有限公司 | 漏洞自动验证方法、装置、设备及存储介质 |
Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN102354310A (zh) * | 2011-07-12 | 2012-02-15 | 广东电网公司信息中心 | 一种自动化信息安全评估的方法及装置 |
CN103065095A (zh) * | 2013-01-29 | 2013-04-24 | 四川大学 | 一种基于指纹识别技术的web漏洞扫描方法和漏洞扫描器 |
CN103581193A (zh) * | 2013-11-08 | 2014-02-12 | 星云融创(北京)信息技术有限公司 | 一种网站漏洞扫描方法、装置及系统 |
CN105468981A (zh) * | 2015-11-20 | 2016-04-06 | 上海斐讯数据通信技术有限公司 | 基于漏洞识别技术的插件安全扫描装置及扫描方法 |
CN106503564A (zh) * | 2016-10-26 | 2017-03-15 | 上海携程商务有限公司 | 软件漏洞的发现方法和系统 |
-
2017
- 2017-09-20 CN CN201710854522.1A patent/CN107508830B/zh active Active
Patent Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN102354310A (zh) * | 2011-07-12 | 2012-02-15 | 广东电网公司信息中心 | 一种自动化信息安全评估的方法及装置 |
CN103065095A (zh) * | 2013-01-29 | 2013-04-24 | 四川大学 | 一种基于指纹识别技术的web漏洞扫描方法和漏洞扫描器 |
CN103581193A (zh) * | 2013-11-08 | 2014-02-12 | 星云融创(北京)信息技术有限公司 | 一种网站漏洞扫描方法、装置及系统 |
CN105468981A (zh) * | 2015-11-20 | 2016-04-06 | 上海斐讯数据通信技术有限公司 | 基于漏洞识别技术的插件安全扫描装置及扫描方法 |
CN106503564A (zh) * | 2016-10-26 | 2017-03-15 | 上海携程商务有限公司 | 软件漏洞的发现方法和系统 |
Non-Patent Citations (1)
Title |
---|
入侵检测系统与漏洞扫描联动的应用研究;唐晓东 等;《网络安全技术与应用》;20140831;第121、123页 * |
Also Published As
Publication number | Publication date |
---|---|
CN107508830A (zh) | 2017-12-22 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN107508830B (zh) | 一种减少网站漏洞扫描漏报的方法 | |
CN107368417B (zh) | 一种漏洞挖掘技术测试模型的测试方法 | |
CN108090567B (zh) | 电力通信系统故障诊断方法及装置 | |
US10303874B2 (en) | Malicious code detection method based on community structure analysis | |
WO2022143145A1 (zh) | 越权漏洞检测方法和装置 | |
US20200104292A1 (en) | Method and apparatus for integrating multi-data source user information | |
CN103279710B (zh) | Internet信息系统恶意代码的检测方法和系统 | |
CN106982194A (zh) | 漏洞扫描方法及装置 | |
WO2017101301A1 (zh) | 数据信息处理方法及装置 | |
CN104346574A (zh) | 基于配置规范的主机安全配置漏洞自动修复方法及系统 | |
CN106294149A (zh) | 一种检测Android应用程序组件通信漏洞的方法 | |
CN107146150A (zh) | 审计对象的审计方法、装置、存储介质及处理器 | |
CN102789502A (zh) | 网站的扫描方法和装置 | |
CN114817968B (zh) | 无特征数据的路径追溯方法、装置、设备及存储介质 | |
CN111027074A (zh) | 一种漏洞自动化利用方法以及系统 | |
TW201843609A (zh) | 用於以學習為基礎的群組標記之系統和方法 | |
CN104506541A (zh) | 网站漏洞告警方法及装置 | |
CN111581110B (zh) | 一种业务数据准确性检测方法、装置、系统及存储介质 | |
Bai et al. | Dynamic k-gram based software birthmark | |
CN106227812A (zh) | 一种数据库对象脚本安全风险的审计方法 | |
CN114844689A (zh) | 一种基于有限状态机的网站逻辑漏洞检测方法及系统 | |
CN111190906B (zh) | 一种传感网数据异常检测方法 | |
WO2020119551A1 (zh) | 基于日志文件的服务性能分析方法、装置及电子设备 | |
CN103309809A (zh) | 一种计算机软件的智能化调试方法 | |
CN114637739B (zh) | 数据库管控方法、系统、计算机设备及计算机存储介质 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
CB02 | Change of applicant information |
Address after: 310051 No. 188 Lianhui Street, Xixing Street, Binjiang District, Hangzhou City, Zhejiang Province Applicant after: Dbappsecurity Co.,Ltd. Address before: Zhejiang Zhongcai Building No. 68 Binjiang District road Hangzhou City, Zhejiang Province, the 310051 and 15 layer Applicant before: Dbappsecurity Co.,ltd. |
|
CB02 | Change of applicant information | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20171222 Assignee: Hangzhou Anheng Information Security Technology Co.,Ltd. Assignor: Dbappsecurity Co.,Ltd. Contract record no.: X2024980043369 Denomination of invention: A method to reduce website vulnerability scanning omissions Granted publication date: 20191108 License type: Common License Record date: 20241231 |
|
EE01 | Entry into force of recordation of patent licensing contract |