节点文献

状态驱动的电力信息系统注人漏洞检测模型

State-driven injection vulnerability detection model for power information system

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 殷博刘磊朱静雯许静

【Author】 YIN Bo;LIU Lei;ZHU Jing-wen;XU Jing;State Grid Tianjin Electric Power Company;College of Artificial Intelligence,Nankai University;College of Software,Nankai University;

【机构】 国网天津市电力公司南开大学人工智能学院南开大学软件学院

【摘要】 SQL注入漏洞是危害最为严重的电力Web信息系统漏洞之一,且其隐蔽性、逻辑性和时序性等特点不断增强,传统漏洞分析方法已难以满足当前的检测要求,造成准确度不足的问题。对此,提出一种状态驱动的电力Web信息系统SQL注入漏洞安全特征分析和检测模型,将攻击语句特征进行状态映射,建立检测过程的扩展有限状态机(extended finite state machine,EFSM),利用相应的状态转换关系来分析识别漏洞特征。实验对比与分析结果表明,该方法可有效提高电力信息系统中SQL注入漏洞渗透测试的准确度,降低其误报和漏报。

【Abstract】 SQL injection vulnerability is one of the most serious vulnerabilities in power Web information system,and its hidden,logical and temporal characteristics are increasingly strengthened,the traditional vulnerability analysis method is difficult to meet the current detection requirements,resulting in insufficient accuracy.A state-driven detection model was presented for the security feature analysis of power Web information system.The attack statement features were mapped to states,and the extended finite state machine(EFSM) of the test process based on the attack statement characteristics was established,and the vulnerability characteristics were analyzed using the corresponding state transition relation.The results show that the proposed method can improve the accuracy of the penetration test of SQL injection in power Web system,and reduce the testing false positives and false negatives.

【基金】 国家电网公司总部科技基金项目(SGTJDK00DWJS1900105)
  • 【文献出处】 计算机工程与设计 ,Computer Engineering and Design , 编辑部邮箱 ,2021年03期
  • 【分类号】TM73;TP393.08
  • 【下载频次】106
节点文献中: 

本文链接的文献网络图示:

本文的引文网络