Automatic penetration testing method and system based on knowledge graph

The invention discloses an automatic penetration testing method and system based on a knowledge graph, and belongs to the technical field of vulnerability detection. The method comprises the following steps: constructing an expert knowledge base, wherein the expert knowledge base comprises a weak pa...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: ZHANG KAI, ZHANG YUE, HOU DONGDONG, ZHOU SHICHENG, YANG GUOZHENG, WANG YONGJIE, LIU JINGJU
Format: Patent
Sprache:chi ; eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:The invention discloses an automatic penetration testing method and system based on a knowledge graph, and belongs to the technical field of vulnerability detection. The method comprises the following steps: constructing an expert knowledge base, wherein the expert knowledge base comprises a weak password knowledge base and a vulnerability knowledge base; wherein weak passwords are stored in the weak password knowledge base, and vulnerability information and corresponding vulnerability detection methods are stored in the vulnerability knowledge base; scanning a target host located in a test network to obtain fingerprint information of the target host, and matching the fingerprint information with vulnerability information in the vulnerability knowledge base to obtain a matched vulnerability and a corresponding vulnerability detection method; and sorting the matched vulnerabilities based on the vulnerability risk values, and according to the sorting, calling the corresponding vulnerability detection methods in