(Enter summary)
Abstract: NetKuang is an extension to Baldwin's SU-Kuang.
It runs on networks of computers using Unix and can
find vulnerabilities created by poor system configuration.
Vulnerabilities are discovered using a backwards
goal-based search that is breadth-first on individual
hosts and parallel when multiple hosts are
checked. An implementation in C++ found real vulnerabilities
on production systems. Tests show reasonably
fast performance on an LAN.
1 Introduction
The security of modern networked computer... (Update)
Context of citations to this paper: More
...have focussed primarily on identification of configuration errors such as improper file permission settings. Existing approaches [11, 4, 21] can be broadly characterized as rule based, i.e. they employ a set of rules that enumerate known causes for vulnerabilities. The...
...analysis has focused primarily on identification of configuration errors such as improper file permission settings. Existing works [2, 11, 23] employ a set of rules that enumerate known causes for vulnerabilities. We call these works collectively rule based. Widely used...
Cited by: More
Using CSP to Model and Analyze Transmission Control Protocol .. - Shahriari, Jalili (2004)
(Correct)
Modeling Multistep Cyber Attacks for Scenario Recognition - Cheung, Lindqvist, Fong (2003)
(Correct)
Automated Analysis for Digital - Forensic Science Semantic (2003)
(Correct)
Active bibliography (related documents): More All
0.5: SAINT: A Security Analysis Integration Tool - Zamboni (1996)
(Correct)
0.5: Composable Tools For Network Discovery and Security Analysis - Vigna, Valeur, Zhou.. (2002)
(Correct)
0.4: Continuous Assessment of a Unix Configuration: Integrating.. - Mounji, Le Charlier (1996)
(Correct)
Similar documents based on text: More All
0.3: A Taxonomy of UNIX System and Network Vulnerabilities - Bishop (1995)
(Correct)
0.3: Vulnerabilities Analysis - Bishop (1999)
(Correct)
0.3: Automated Detection of Vulnerabilities in Privileged.. - Ko, Fink, Levitt (1994)
(Correct)
Related documents from co-citation: More All
4: The COPS security checker system
- Farmer, Spafford - 1990
4: Using Model Checking to Analyze Network Vulnerabilities (context) - Ritchey, Ammann - 2000
3: The Temporal Logic of Reactive and Concurrent Systems (context) - Manna, Pnueli - 1992
BibTeX entry: (Update)
D. Zerkle and K. Levitt. NetKuang --- A Multi-Host Configuration Vulnerability Checker. In 6 th USENIX Security Symposium, San Jose, California, July 1996. http://seclab.cs.ucdavis.edu/papers/zl96.ps. 9 of http://citeseer.ist.psu.edu/zerkle96netkuang.html More
@inproceedings{ zerkle96netkuang,
author = "Dan Zerkle and Karl Levitt",
title = "{NetKuang--A} Multi-Host Configuration Vulnerability Checker",
pages = "195--201",
year = "1996",
url = "citeseer.ist.psu.edu/zerkle96netkuang.html" }
Citations (may not include all citations):
46
The cops security checker system
- Farmer, Spafford - 1990 DBLP
6
Specifying and checking unix security constraints
- Heydon - 1992 ACM DBLP
4
Kuang: Rule-based security checking (context) - Baldwin
3
Security administrator's tool for analyzing networks (context) - Farmer, Venema
2
The design of a system integrity monitor: Tripwire (context) - Kim, Spafford - 1993
2
Internet scanner (context) - Systems
The graph only includes citing articles where the year of publication is known.
Documents on the same site (http://www.netsys.com/firewalls/firewalls-9708/0041.html):
Checking for Race Conditions in File Accesses - Matt Bishop (1996)
(Correct)
A Methodology for Testing Intrusion Detection Systems - Puketza, Zhang, Chung.. (1996)
(Correct)
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC