The invention provides an automatic permeability test
system for a
WEB system, comprising three
layers: a GUI
presentation layer for alternating interface with a user, a
logical layer as runs of control core, executing scanning and confidence program of the
system and associative functions, and a data layer for storing and maintaining kinds of scan rules and configuration information in a task execution process. The
system can automatically carry out a penetrating scan or a conventional scan to a WEB
station based on a WEB scan task in the GUI layer, analyzing the scan result combined with the relative inserters, finds the possible security problems of the WEB
station, and then generates a detecting report for reporting a formed aggregate risk
list. The invention is used to perform an automatic security test, is capable of replacing the present manual security test and permeability test, greatly reduces the cost of
software security test in
software develop at present, and also greatly increases accuracy of security test.