作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (9): 186-188,. doi: 10.3969/j.issn.1000-3428.2008.09.067

• 安全技术 • 上一篇    下一篇

基于表单爬虫的Web漏洞探测

赵 亭,陆余良,刘金红,孙宏纲,施 凡   

  1. (合肥电子工程学院网络工程系,合肥 230037)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-05-05 发布日期:2008-05-05

Web Vulnerability Detection Based on Form Crawler

ZHAO Ting, LU Yu-liang, LIU Jin-hong, SUN Hong-gang, SHI Fan   

  1. (Network Engineering Laboratory, Electronic Engineering Institute, Hefei 230037)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-05-05 Published:2008-05-05

摘要: 提出基于滑动窗口的自适应站点搜索策略和基于位置特征与复现频率的导航链接发现策略。在此基础上,采用基于导航链接的表单搜索策略,设计一种新颖的不同于普通爬虫和主题爬虫的表单爬虫。给出一个基于表单爬虫的Web漏洞探测方案。实验表明该方案搜索表单的收益率和覆盖率分别达到了24%和85%,对跨站攻击漏洞的探测准确率达到96%。

关键词: 表单爬虫, 收益率, 覆盖率, 精确率, 召回率

Abstract: This paper proposes an adaptive site-search strategy based on glide window and a navigation link searching strategy based on both location and the frequency of appearance. A new form crawler is designed which is different from common crawler or topic crawler. The form crawler utilizes navigation link to search form. Then a new Web vulnerability detecting scheme is proposed based on the form crawler. It is proved that the harvest and coverage of form searching reaches 24% and 85% respectively, and the accuracy of XSS detection reaches 96%.

Key words: form crawler, harvest, coverage, accuracy, recall

中图分类号: