首页> 外文会议>International conference on information and communications security >Parameter Pollution Vulnerabilities Detection Study Based on Tree Edit Distance
【24h】

Parameter Pollution Vulnerabilities Detection Study Based on Tree Edit Distance

机译:基于树编辑距离的参数污染漏洞检测研究

获取原文

摘要

A new web attack pattern called HTTP Parameter Pollution has been presented in recent years. The harm and detection method about HPP has become a hot topic in the field of web application security. In the paper, we started with analyzing the HPP attack pattern, researched on the necessary conditions and the potential harm of attack, pointed that the determination of parameter precedence is a prerequisite for the implementation and testing of such attacks, and proposed determination method for parameter priority based on tree edit distance to provide the necessary support for HPP vulnerabilities detection. As well as, we developed different detection methods for the difference of parameters between URL and the page. Finally the detection system for HPP vulnerability was realized, and some vulnerabilities have been discovered in real world.
机译:近年来,出现了一种新的Web攻击模式,称为HTTP参数污染。 HPP的危害和检测方法已成为Web应用程序安全领域的热门话题。本文从分析HPP攻击模式入手,研究了攻击的必要条件和潜在危害,指出确定参数优先级是实施和测试此类攻击的先决条件,并提出了确定参数的方法基于树编辑距离的优先级,为HPP漏洞检测提供必要的支持。此外,我们针对URL和页面之间的参数差异开发了不同的检测方法。最终实现了HPP漏洞检测系统,并在现实世界中发现了一些漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号