Beyond Internet Scanning: Banner Processing for Passive Software Vulnerability Assessment
نویسندگان
چکیده
Nowadays, the increasing number of devices and services that require a direct Internet access, creates new security challenges. These challenges need to meet user feature-based requirements with the companies’ restrictive security policies. Therefore, security administrators need to adopt novel tools in order to quickly and non-intrusively verify the degree of exposure of Internet-facing services. In this respect, we find tools such as Shodan and ZMap, which enable scanning of services at an Internetscale. Scan results can deliver significant details on service version, patches, and configuration. Subsequently, these can expose valuable information about known software vulnerabilities, which may be exploited by malicious actors. Therefore, this work studies the degree of service exposure by means of banner analysis. Experiments conducted on five university-type institutions revealed that banner analysis is not “old fashioned” and that immediate measures need to be taken in order to secure sensitive services. Keywords—Vulnerability assessment; Internet scanning; Common Platform Enumeration (CPE); Common Vulnerability and Exposure (CVE); National Vulnerability Database (NVD).
منابع مشابه
Assessment of Urban Spaces Based on the Principles of Passive Defense; Case Study of Enghelab Square Area, Tehran, Iran
Aims: Reducing the city's vulnerability in times of crisis and emergencies is part of the urban design mission. Hence, passive defense measures have been developed to reduce the vulnerability of cities in times of crisis. The purpose of this study was to identify the factors affecting passive defense in the performance of urban spaces in the area of Enghelab Square in Tehran. Methodology: This ...
متن کاملShoVAT: Shodan-based vulnerability assessment tool for Internet-facing services
Shodan has been acknowledged as one of the most popular search engines available today, designed to crawl the Internet and to index discovered services. This paper expands the features exposed by Shodan with advanced vulnerability assessment capabilities embedded into a novel tool called ShoVAT. ShoVAT takes the output of traditional Shodan queries and performs an in-depth analysis of service-s...
متن کاملAssessment the Vulnerability of Infrastructures in Ardabil City in terms of passive defense
At the moment with regard to geopolitical and geostrategic situation of Iran, the existence of countless underground resources and the formation of ideological state, unfortunately, in urban areas of the country, especially in Ardabil ,because of its proximity to the border of northern and northwestern borders with knowledge of this particular situation, economic and infrastructural projects, I...
متن کاملCity Vulnerability Assessment with Passive Defense Approach; A Case Study: Rasht City, Iran
BACKGROUND: The passive defense approach is one of the approaches in planning and organizing cities and residential complexes with the aim to reduce environmental hazards. Given the vital and sensitive position of cities, while preparing against military invasions, this approach provides special capabilities to cope with natural and human crises to a large extent. METHODS: This was an applied s...
متن کاملWhy and When Will Banner Blindness Occur? An Analysis Based on the Dual Processing Theory
As an advertising tool, banners have been widely adopted by online marketers. However, because of low click-through rates, banners’ effectiveness has been questioned. A phenomenon called “banner blindness” suggests that salient stimuli, such as banners, are often missed by Internet users. This contradicts the distinctiveness view which argues that salient stimuli are more likely to attract user...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2015