计算机工程与应用 ›› 2009, Vol. 45 ›› Issue (36): 82-85.DOI: 10.3778/j.issn.1002-8331.2009.36.024

• 网络、通信、安全 • 上一篇    下一篇

兼容OVAL的多平台VAS设计与实现

王旭冬,高 岭,张 林   

  1. 西北大学 信息科学与技术学院,西安 710127
  • 收稿日期:2008-12-26 修回日期:2009-03-05 出版日期:2009-12-21 发布日期:2009-12-21
  • 通讯作者: 王旭冬

Design and implementation of OVAL-compatible VAS on multi-platform

WANG Xu-dong,GAO Ling,ZHANG Lin   

  1. Department of Information Science and Technology,Northwest University,Xi’an 710127,China
  • Received:2008-12-26 Revised:2009-03-05 Online:2009-12-21 Published:2009-12-21
  • Contact: WANG Xu-dong

摘要: 针对不同厂商安全软件之间的信息表示格式差异带来的软件联动问题,以及一个网络内通常存在多种平台主机的现状,提出一种“管理者/代理”架构的、兼容OVAL的多平台VAS(弱点评估系统)。系统以OVAL作为弱点评估标准,以轻量级Web server为通讯手段,支持多平台主机弱点评估,在保证评估高精度的同时,支持与OVAL兼容的其他安全软件共享安全数据,具有更高的评估完备性和功能扩展性。

Abstract: Aiming at the flaws of current interoperability problem brought by different information expressing standards between different security products and present situation that a network generally includes several kinds of platforms,a design of manager/agent architecture-based,OVAL-compatible multi-platform Vulnerability Assessment System(VAS) is given.This system takes OVAL as vulnerability assessment standard and takes lightweight Web server as communicating measure.It supports multi-platform vulnerability assessment and sharing security data with other OVAL-compatible tools with high accuracy,assessing completeness and functional expansibility.

中图分类号: