GB/T 20280-2006 in English
SUPERSEDEDInformation security technology - Testing and evaluation approaches for network vulnerability scanners
- Issued on:2006-05-31
- Implemented on:2006-12-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$127.00
《GB/T 20280-2006信息安全技术 网络脆弱性扫描产品测试评价方法》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
本标准规定了对采用传输控制协议和网际协议(TCP/IP)的网络脆弱性扫描产品的测试、评价方法。本标准适用于对计算机信息系统进行人工或自动的网络脆弱性扫描的安全产品的评测、研发和应用。本标准不适用于专门对数据库系统进行脆弱性扫描的产品。
1 Scope
This Standard specifies the testing and evaluation approaches for network vulnerability scanners adopting Transmission Control Protocol and Internet Protocol (TCP/IP).
This Standard is applicable to the testing and evaluation, R&D and application of security products for manual or automatic network vulnerability scan on computer information system.
This Standard is not applicable to products specialized for vulnerability scan on database system.
2 Normative References
The following standard contains provisions which, by reference into this document, constitute the provisions of this document. For dated reference, subsequent amendments to (excluding correction contents), or revisions of, any of these publications do not apply. However, it is encouraged that the Parties that reach an agreement according to this Standard should research whether the latest edition of these documents can be used. For undated references, their latest editions apply.
GB/T 5271.8-2001 Information Technology – Vocabulary - Part 8: Security (idt ISO/IEC 2382-8: 1998)
GB/T 20278-2006 Information Security Technology Technique Requirement for Network Vulnerability Scanners
: 3 Terms and Definitions
For the purpose of this Standard, terms and definitions established in GB/T 5271.8-2001 and GB/T 20278-2006 apply.
4 Stipulation of Symbol, Abbreviation and Notation
4.1 Symbols and Abbreviations
CGI Common Gateway Interface
CVE Common Vulnerabilities and Exposures
DNS Domain Name System
DOS Denial of Service
FTP File Transfer Protocol
IDS Intrusion Detection System
IP Internet Protocol
NETBIOS Network Basic Input Output System
NFS Network File System
POP Post Office Protocol
RPC Remote Procedure Call
SMB Server Message Block Protocol
SNMP Simple Network Management Protocol
TCP Transport Control Protocol
UDP User Datagram Protocol
4.2 Stipulation of Notation
Foreword I
Introduction II
1 Scope
2 Normative References
:
3 Terms and Definitions
4 Stipulation of Symbol, Abbreviation and Notation
4.1 Symbols and Abbreviations
4.2 Stipulation of Notation
5 Overview of Network Vulnerability Scanners
6 Testing Environment
7 Testing and Evaluation Approaches and Procedure
7.1 Basic Type
7.1.1 Basic function
7.1.3 Security assurance requirements
7.2 Enhanced Type
7.2.1 Basic function and performance
7.2.2 Enhancement function
7.2.3 Security assurance requirements
Appendix A (Normative) Testing Evidence Provided by Product Manufacturer to Testing Unit
A.1 Basic Type
A.2 Enhanced Type
Bibliography

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 17901.1-2020 in English
Information technology—Security techniques—Key management—Part 1: Framework
2020-03-06 -

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 20009-2019 in English
Information security technology—Security evaluation criteria for database management system
2019-08-30 -

GB/T 22186-2016 in English
Information security techniques―Security technical requirements for IC card chip with CPU
2016-08-29 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 36323-2018 in English
Information security technology--Security management fundamental requirements for industrial control systems
2018-06-07