首页> 外文会议>International conference on swarm intelligence >The Design and Implementation of the Random HTML Tags and Attributes-Based XSS Defence System
【24h】

The Design and Implementation of the Random HTML Tags and Attributes-Based XSS Defence System

机译:基于随机HTML标签和属性的XSS防御系统的设计与实现

获取原文

摘要

At present, cross site scripting (XSS) is still one of the biggest threat for Internet security. But the defensive approach is still feature matching mostly; that is, to check for a matching and filter in all information submitted. However, filtering technology has many disadvantages as heavy-workload, complex-operation, high-risk and so on. For this reason, our system use the randomization techniques of HTML tags and attributes innovatively, based on the prefix of HTML tags and attributes, to determine the tags and attributes are Web designers expect to generate or other users insert in, and then we follow the results to carry out different policies, only tags and attributes that Web designers expected to generate can be rendered and implemented. By this way, we can defend against XSS attacks completely. The test results show that the system is able to solve a variety of problems in filtering technology. It uses simple and convenient operation and safe and secure effect to free developers from heavy filtering work. System has a good compatibility and portability across platforms, it also can connect with all web-based applications seamlessly. In all, system defend against XSS better and meet the need of today's XSS attacks defence.
机译:目前,跨站点脚本(XSS)仍然是Internet安全的最大威胁之一。但是,防御方法仍然主要是特征匹配。也就是说,检查是否匹配并过滤所有提交的信息。但是,过滤技术具有工作量大,操作复杂,高风险等缺点。因此,我们的系统基于HTML标签和属性的前缀创新地使用了HTML标签和属性的随机化技术,以确定Web设计人员期望生成的标签或属性或其他用户插入的标签和属性,然后按照执行不同策略的结果,只能呈现和实现Web设计人员期望生成的标签和属性。这样,我们可以完全防御XSS攻击。测试结果表明,该系统能够解决滤波技术中的各种问题。它使用简单方便的操作以及安全可靠的效果使开发人员免于繁重的筛选工作。系统具有良好的兼容性和跨平台的可移植性,它还可以与所有基于Web的应用程序无缝连接。总之,系统可以更好地防御XSS,并满足当今XSS攻击防御的需求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号