首页> 外文会议>Proceedings of the 9th international conference for young computer scientists (ICYCS 2008) >A Hybrid Vulnerability Analysis Method against non-Security Protocols
【24h】

A Hybrid Vulnerability Analysis Method against non-Security Protocols

机译:针对非安全协议的混合漏洞分析方法

获取原文

摘要

A hybrid analysis method for protocol is proposed which combines the power of both manual and automatic methods. At first, it defines a number of attack goals and then studies how to achieve these goals by misusing the messages. An automatic analysis tool is applied in order to reach completeness based on the manual analysis. Some of the found attacks are excluded because of the low feasibility in the practical environment, and the other feasible attacks might be combined to launch more powerful compound attacks. Some vulnerability is found when applying the hybrid method to check mobile IPv6 protocol. The result shows the hybrid method is a systematic method with completeness guarantee. It fits for analyzing non-security protocols and finding the subtle vulnerability.
机译:提出了一种用于协议的混合分析方法,该方法结合了手动方法和自动方法的强大功能。首先,它定义了多个攻击目标,然后研究了如何通过滥用消息来实现这些目标。为了达到基于手动分析的完整性,使用了自动分析工具。由于在实际环境中可行性较低,因此排除了一些已发现的攻击,而其他可能的攻击可能会组合起来以发起更强大的复合攻击。应用混合方法检查移动IPv6协议时发现一些漏洞。结果表明,混合方法是一种具有完整性保证的系统方法。它适合于分析非安全协议并找到细微的漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号