Website Scanning Device Using Change Judgment for Vulnerability Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional full vulnerability scanning of websites is resource-intensive, causing significant bandwidth usage and server load, and is inefficient as it scans all web pages regardless of changes, leading to prolonged scanning times and increased server pressure.
Innovation Solution
A website scanning apparatus and method that selectively performs security vulnerability scanning only on web pages that have changed since the last scan, using a change judgment device to identify altered pages and perform detection only on those, thereby reducing unnecessary scans and server load.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full vulnerability scanning is performed on all web pages, then scanning comprehensiveness is improved, but scanning time and server load increase significantly
Solution Approach 1:
The patent segments the vulnerability scanning process into two parts: a comprehensive full scanning phase that scans all web pages to identify vulnerabilities, and an incremental scanning phase that only scans changed pages between updates. This segmentation allows the system to maintain thorough scanning coverage while significantly reducing the time and resources required for repeated scanning operations.
Solution Approach 2:
The patent performs a preliminary full vulnerability scan to establish a baseline of all web pages and their vulnerability status. This preliminary action creates a reference database that enables subsequent incremental scans to focus only on changed pages, thereby reducing the time and server load required for repeated scanning operations.
2Reliability
If full vulnerability scanning is performed frequently, then security detection accuracy is improved, but server processing pressure increases
Solution Approach 1:
The patent applies local quality by transitioning from uniform full scanning of all pages to selective scanning only of changed pages. This allows the scanning resource to be concentrated locally on pages that actually changed, maintaining security detection accuracy for affected areas while significantly reducing the overall server processing pressure during incremental scans.
Solution Approach 2:
The patent implements partial action by performing vulnerability scanning only on the subset of web pages that have changed since the last scan, rather than scanning all pages repeatedly. This partial scanning approach maintains sufficient security detection accuracy for changed content while reducing server processing pressure compared to full repeated scanning.
3Reliability
If vulnerability scanning is performed on unchanged web pages, then scanning completeness is improved, but scanning efficiency decreases
Solution Approach 1:
The patent introduces dynamics by adapting the scanning strategy based on page change status. The system dynamically switches between full scanning mode (for new or changed pages) and incremental scanning mode (for unchanged pages), allowing scanning efficiency to be optimized according to the actual state of web pages while maintaining completeness where needed.
Solution Approach 2:
The patent changes the scanning parameter from a fixed full-scanning approach to a variable approach that adjusts the scope of scanning based on page change detection. By detecting whether pages have changed and adjusting the scanning parameter accordingly (full scan vs. incremental scan), the system maintains scanning completeness for changed content while significantly improving overall scanning efficiency.
Data Source
AI summary
The invention discloses a website scanning apparatus for performing a security vulnerability scanning on a target website, which apparatus comprises: a web page obtaining component obtaining current content and/or features of a web page corresponding to a link to be processed; a link processing component including a change judgment device for judging whether the web page corresponding to the link to be processed has been changed based on stored web page content and/or features corresponding to the link to be processed as well as the current web page content and/or features of the link to be processed; and a vulnerability detecting component for performing a security vulnerability detection on a web page corresponding to a link to be processed for which the web page has been changed. The invention also discloses a website scanning method corresponding thereto.


