节点文献
状态驱动的电力信息系统注人漏洞检测模型
State-driven injection vulnerability detection model for power information system
【摘要】 SQL注入漏洞是危害最为严重的电力Web信息系统漏洞之一,且其隐蔽性、逻辑性和时序性等特点不断增强,传统漏洞分析方法已难以满足当前的检测要求,造成准确度不足的问题。对此,提出一种状态驱动的电力Web信息系统SQL注入漏洞安全特征分析和检测模型,将攻击语句特征进行状态映射,建立检测过程的扩展有限状态机(extended finite state machine,EFSM),利用相应的状态转换关系来分析识别漏洞特征。实验对比与分析结果表明,该方法可有效提高电力信息系统中SQL注入漏洞渗透测试的准确度,降低其误报和漏报。
【Abstract】 SQL injection vulnerability is one of the most serious vulnerabilities in power Web information system,and its hidden,logical and temporal characteristics are increasingly strengthened,the traditional vulnerability analysis method is difficult to meet the current detection requirements,resulting in insufficient accuracy.A state-driven detection model was presented for the security feature analysis of power Web information system.The attack statement features were mapped to states,and the extended finite state machine(EFSM) of the test process based on the attack statement characteristics was established,and the vulnerability characteristics were analyzed using the corresponding state transition relation.The results show that the proposed method can improve the accuracy of the penetration test of SQL injection in power Web system,and reduce the testing false positives and false negatives.
【Key words】 power information system; security vulnerabilities; extended finite state machine; security test; SQL injection vulnerability;
- 【文献出处】 计算机工程与设计 ,Computer Engineering and Design , 编辑部邮箱 ,2021年03期
- 【分类号】TM73;TP393.08
- 【下载频次】106