计算机与现代化 ›› 2014, Vol. 0 ›› Issue (8): 67-70+80.doi: 10.3969/j.issn.1006-2475.2014.08.015

• 信息安全 • 上一篇    下一篇

基于主题爬虫的漏洞库维护系统

  

  1. (装甲兵工程学院信息工程系,北京100072)
  • 收稿日期:2014-06-06 出版日期:2014-08-15 发布日期:2014-08-19
  • 作者简介:刘海燕(1970-),女,河北遵化人,装甲兵工程学院信息工程系教授,博士,研究方向:网络安全; 黄睿(1989-),男,河北石家 庄人, 硕士研究生,研究方向:网络安全。

Vulnerability Database Maintenance System Based on Topic Web Crawler

  1. (Department of Information Engineering, Academy of Armored Force Engineering, Beijing 100072, China)
  • Received:2014-06-06 Online:2014-08-15 Published:2014-08-19

摘要:

漏洞库是用来存储漏洞信息的数据库,是信息安全基础设施的重要组成部分。将主题爬虫技术引入漏洞数据库的维护工作,通过
主题网络爬虫获取与“漏洞”相关的网页,从中提取漏洞信息来更新漏洞数据库,降低了人工维护的工作量,改善了现有漏洞库存在漏
洞覆盖不全面、内容不丰富的问题。分析当前国内外主要漏洞库的结构特征,研究漏洞诸多属性间的关系,运用组群分类描述法构建漏
洞库结构模型。在研究主题网络爬虫的基础上,提出一种面向漏洞主题的动态主题构建方案。介绍漏洞库维护系统的总体设计和实现方
法。

关键词: 主题爬虫, 动态主题, 漏洞模型, 漏洞库

Abstract:

Vulnerability database is an important part of information security infrastructure used for storing
vulnerability information. This paper introduced topic Web crawler into the vulnerability database maintenance
system, in which the webpages that are related to vulnerabilities can be accessed through topic Web crawler and
the vulnerability information can be abstracted so as to update the vulnerability database. This technology
reduced the workload of maintenance and resolved the problems of coverage incompletion and lack of information in
the existing vulnerability database. By analyzing the structure of the existing vulnerability database at home and
abroad, studying the association of vulnerability attributes, and implementing group classification description
method, this paper built a vulnerability database syntactic model. It also came up with a dynamic topic
construction scheme for vulnerability topic, introducing design and implementation of vulnerability database
maintenance system.

Key words: topic Web crawler, dynamic topic, vulnerability model, vulnerability database

中图分类号: