期刊论文详细信息
网络与信息安全学报
Automatic detection method of software upgradevulnerability based on network traffic analysis
TENG Jinhui, GUANG Yan, SHU Hui, ZHANG Bing1 
[1] Strategic Support Force Information Engineering University, Zhengzhou 450001, China;
关键词: software upgrade;    network traffic analysis;    vulnerability detection;    automated analysis and validation;   
DOI  :  10.11959/j.issn.2096-109x.2020004
来源: DOAJ
【 摘 要 】

During the software upgrade process, the lack of authentication for upgrade information or packages can lead to remote code execution vulnerabilities based on man-in-the-middle attack. An automatic detection method for upgrading vulnerabilities was proposed. The method described the upgrade mechanism by extracting the network traffic during the upgrade process, then matched it with the vulnerability feature vector to anticipate upgrading vulnerabilities. In a validation environment, the man-in-the-middle attack using the portrait information was carried out to verify the detection results. In addition, an automatic vulnerability analysis and verification system based on this method was designed. 184 Windows applications samples was test and 117 upgrade vulnerabilities were detected in these samples, which proved validity of the method.

【 授权许可】

Unknown   

  文献评价指标  
  下载次数:0次 浏览次数:0次