Benchmarking vulnerability scanners: An experiment on SCADA devices and scientific instruments

Benchmarking vulnerability scanners: An experiment on SCADA devices and scientific instruments
复制标题

漏洞扫描仪基准测试:SCADA 设备和科学仪器的实验

DOI:
--
复制
发表时间:
2017
期刊:
Intelligence and Security Informatics
影响因子:
--
通讯作者:
Hsinchun Chen
Hsinchun Chen
中科院分区:
--
文献类型:
--
作者:
Malaka El;Emma McMahon;Sagar Samtani;Mark W. Patton;Hsinchun Chen

文献摘要

被引文献

相似文献

网络安全是当今社会的一个关键问题。恶意黑客常用的一种攻击途径是利用存在漏洞的网站。据估计,每天有超过一百万个网站受到攻击。此类攻击的两个新兴目标是监控与数据采集(SCADA)设备和科学仪器。漏洞评估工具可以帮助这些设备的所有者了解如何保护其基础设施。然而,所有者在确定哪些工具适合其评估方面面临困难。本研究旨在针对SCADA设备和科学仪器,对两款最先进的漏洞评估工具——Nessus和Burp Suite进行基准测试。我们特别关注识别扫描的准确性、可扩展性和漏洞结果。我们的研究结果表明,这两种工具结合使用可以对SCADA设备和科学仪器中的漏洞进行全面评估。
Cybersecurity is a critical concern in society today. One common avenue of attack for malicious hackers is exploiting vulnerable websites. It is estimated that there are over one million websites that are attacked daily. Two emerging targets of such attacks are Supervisory Control and Data Acquisition (SCADA) devices and scientific instruments. Vulnerability assessment tools can help provide owners of these devices with the knowledge on how to protect their infrastructure. However, owners face difficulties in identifying which tools are ideal for their assessments. This research aims to benchmark two state-of-the-art vulnerability assessment tools, Nessus and Burp Suite, in the context of SCADA devices and scientific instruments. We specifically focus on identifying the accuracy, scalability, and vulnerability results of the scans. Results of our study indicate that both tools together can provide a comprehensive assessment of the vulnerabilities in SCADA devices and scientific instruments.