See this document in CiteSeerX!

NetKuang - A Multi-Host Configuration Vulnerability Checker (1996)  (Make Corrections)  (7 citations)
Dan Zerkle and Karl Levitt Department of Computer Science University of...



  Home/Search   Context   Related

 
View or download:
ucdavis.edu/papers/zl96.ps
Cached:  PS.gz  PS  PDF   Image  Update  Help

From:  netsys.com/firewalls/firew...0041 (more)
(Enter author homepages)

Rate this article: (best)
  Comment on this article  
(Enter summary)

Abstract: NetKuang is an extension to Baldwin's SU-Kuang. It runs on networks of computers using Unix and can find vulnerabilities created by poor system configuration. Vulnerabilities are discovered using a backwards goal-based search that is breadth-first on individual hosts and parallel when multiple hosts are checked. An implementation in C++ found real vulnerabilities on production systems. Tests show reasonably fast performance on an LAN. 1 Introduction The security of modern networked computer... (Update)

Context of citations to this paper:   More

...have focussed primarily on identification of configuration errors such as improper file permission settings. Existing approaches [11, 4, 21] can be broadly characterized as rule based, i.e. they employ a set of rules that enumerate known causes for vulnerabilities. The...

...analysis has focused primarily on identification of configuration errors such as improper file permission settings. Existing works [2, 11, 23] employ a set of rules that enumerate known causes for vulnerabilities. We call these works collectively rule based. Widely used...

Cited by:   More
Using CSP to Model and Analyze Transmission Control Protocol .. - Shahriari, Jalili (2004)   (Correct)
Modeling Multistep Cyber Attacks for Scenario Recognition - Cheung, Lindqvist, Fong (2003)   (Correct)
Automated Analysis for Digital - Forensic Science Semantic (2003)   (Correct)

Active bibliography (related documents):   More   All
0.5:   SAINT: A Security Analysis Integration Tool - Zamboni (1996)   (Correct)
0.5:   Composable Tools For Network Discovery and Security Analysis - Vigna, Valeur, Zhou.. (2002)   (Correct)
0.4:   Continuous Assessment of a Unix Configuration: Integrating.. - Mounji, Le Charlier (1996)   (Correct)

Similar documents based on text:   More   All
0.3:   A Taxonomy of UNIX System and Network Vulnerabilities - Bishop (1995)   (Correct)
0.3:   Vulnerabilities Analysis - Bishop (1999)   (Correct)
0.3:   Automated Detection of Vulnerabilities in Privileged.. - Ko, Fink, Levitt (1994)   (Correct)

Related documents from co-citation:   More   All
4:   The COPS security checker system - Farmer, Spafford - 1990
4:   Using Model Checking to Analyze Network Vulnerabilities (context) - Ritchey, Ammann - 2000
3:   The Temporal Logic of Reactive and Concurrent Systems (context) - Manna, Pnueli - 1992

BibTeX entry:   (Update)

D. Zerkle and K. Levitt. NetKuang --- A Multi-Host Configuration Vulnerability Checker. In 6 th USENIX Security Symposium, San Jose, California, July 1996. http://seclab.cs.ucdavis.edu/papers/zl96.ps. 9 of http://citeseer.ist.psu.edu/zerkle96netkuang.html   More

@inproceedings{ zerkle96netkuang,
    author = "Dan Zerkle and Karl Levitt",
    title = "{NetKuang--A} Multi-Host Configuration Vulnerability Checker",
    pages = "195--201",
    year = "1996",
    url = "citeseer.ist.psu.edu/zerkle96netkuang.html" }
Citations (may not include all citations):
46   The cops security checker system - Farmer, Spafford - 1990  DBLP
6   Specifying and checking unix security constraints - Heydon - 1992  ACM   DBLP
4   Kuang: Rule-based security checking (context) - Baldwin
3   Security administrator's tool for analyzing networks (context) - Farmer, Venema
2   The design of a system integrity monitor: Tripwire (context) - Kim, Spafford - 1993
2   Internet scanner (context) - Systems



The graph only includes citing articles where the year of publication is known.


Documents on the same site (http://www.netsys.com/firewalls/firewalls-9708/0041.html):
Checking for Race Conditions in File Accesses - Matt Bishop (1996)   (Correct)
A Methodology for Testing Intrusion Detection Systems - Puketza, Zhang, Chung.. (1996)   (Correct)

Online articles have much greater impact   More about CiteSeer.IST   Add search form to your site   Submit documents   Feedback  

CiteSeer.IST - Copyright Penn State and NEC