BibTex RIS Kaynak Göster
Yıl 2015, Cilt: 4 Sayı: 3, 81 - 91, 29.09.2015

Öz

Beyond Internet Scanning: Non-Intrusive Vulnerability Assessment of Internet-Facing Services

Yıl 2015, Cilt: 4 Sayı: 3, 81 - 91, 29.09.2015

Öz

Nowadays, the increasing number of devices and services that require a direct Internet access, creates new security challenges. These challenges need to meet user feature-based requirements with the companies' restrictive security policies. Therefore, security administrators need to adopt novel tools in order to quickly and non-intrusively verify the degree of exposure of Internet-facing services. In this respect, we find tools such as Shodan and ZMap which enable scanning of services at an Internet-scale. This paper presents a methodology that expands the feature delivered by such tools with automated vulnerability assessment capabilities. The proposed methodology builds on the results returned by Shodan, which are analyzed in order to automatically identify known vulnerabilities from National Vulnerability Database. Experiments conducted on five university-type institutions revealed the effectiveness of the proposed approach and the high degree of service exposure which may require immediate, yet simple service sanitizing security measures.

Toplam 0 adet kaynakça vardır.

Ayrıntılar

Birincil Dil İngilizce
Bölüm Makaleler
Yazarlar

Bela Genge Bu kişi benim

Piroska Haller Bu kişi benim

Calin Enachescu Bu kişi benim

Yayımlanma Tarihi 29 Eylül 2015
Gönderilme Tarihi 30 Ocak 2016
Yayımlandığı Sayı Yıl 2015 Cilt: 4 Sayı: 3

Kaynak Göster

IEEE B. Genge, P. Haller, ve C. Enachescu, “Beyond Internet Scanning: Non-Intrusive Vulnerability Assessment of Internet-Facing Services”, IJISS, c. 4, sy. 3, ss. 81–91, 2015.