首页> 外文会议>2011 Sixth International Conference on Availability, Reliability and Security >Early Detection of Security Misconfiguration Vulnerabilities in Web Applications
【24h】

Early Detection of Security Misconfiguration Vulnerabilities in Web Applications

机译:早期发现Web应用程序中的安全性配置错误

获取原文

摘要

This paper presents a web-based tool to supplement defense against security misconfiguration vulnerabilities in web applications. The tool automatically audits security configuration settings of server environments in web application development and deployment. It also offers features to automatically adjust security configuration settings and quantitatively rates level of safety for server environments before deploying web applications. Using the tool, we were able to evaluate eleven server packages for Apache, PHP and MySQL across three operating system platforms. Our evaluation revealed that the tool is able to audit current security configuration settings and alert users to fix the server environment to achieve the level of safety of security configuration with respect to recommended configurations for real-life web application deployment.
机译:本文提出了一种基于Web的工具,以补充针对Web应用程序中安全配置错误的防御措施。该工具会自动审核Web应用程序开发和部署中服务器环境的安全配置设置。它还提供了一些功能,可以在部署Web应用程序之前为服务器环境自动调整安全配置设置并定量评估安全级别。使用该工具,我们能够在三个操作系统平台上评估针对Apache,PHP和MySQL的十一个服务器软件包。我们的评估表明,该工具能够审核当前的安全配置设置,并提醒用户修复服务器环境,以实现针对实际Web应用程序部署的推荐配置而达到的安全配置安全级别。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号