发明名称 SYSTEM AND METHOD FOR EXTENDING AUTOMATED PENETRATION TESTING TO DEVELOP AN INTELLIGENT AND COST EFFICIENT SECURITY STRATEGY
摘要 A system and method for extending automated penetration testing of a target network is provided. The method comprises: computing a scenario, comprises the steps of: translating a workspace having at least one target computer in the target network, to a planning definition language, translating penetration modules available in a penetration testing framework to a planning definition language, and defining a goal in the target network and translating the goal into a planning definition language; building a knowledge database with information regarding the target network, properties of hosts in the network, parameters and running history of modules in the penetration testing framework; and running an attack plan solver module, comprising: running an attack planner using the scenario as input, to produce at least one attack plan that achieves the goal, and executing actions defined in the at least one attack plan against the target network from the penetration testing framework.
申请公布号 EP2462716(A4) 申请公布日期 2016.04.13
申请号 EP20100807189 申请日期 2010.08.05
申请人 CORE SDI, INCORPORATED 发明人 LUCANGELI OBES, JORGE;SARRAUTE YAMADA, CARLOS, EMILIO;RICHARTE, GERARDO, GABRIEL
分类号 H04L29/06;G06F21/57 主分类号 H04L29/06
代理机构 代理人
主权项
地址