首页> 外文会议>IEEE International Conference on Anti-counterfeiting, Security, and Identification >Improvement in diversify active defense for web application by using language and database heterogeneity
【24h】

Improvement in diversify active defense for web application by using language and database heterogeneity

机译:通过使用语言和数据库异构性来改进Web应用程序的主动防御的多样性

获取原文

摘要

According to OWASP selected web application Top 10 vulnerabilities in 2013 and 2017, structured query language (SQL) injection is consistently ranked the 1st. Therefore, the protection of SQL injection, which is one of the most prevalent and pernicious security issues, requires strengthening. Furthermore, there are numerous unknown vulnerabilities and potential threats in cyber-space. In this case, the active defense based on structural diversity can play an effective role to prevent the hacker from exploiting known or unknown vulnerabilities. And on the basis of structural diversity, we propose a modified method, heterogeneous language, combined with heterogeneous database in data storage layer, to establish an active defense model for data security. We empirically assess the impact of the vulnerability and conclude by testing the accuracy and performance, showing that our security model can not suffer from the same vulnerability as the unprotected one. Finally, the future work and research direction are discussed.
机译:根据OWASP选定的Web应用程序在2013年和2017年的十大漏洞,结构化查询语言(SQL)注入一直排名第一。因此,作为最普遍和最有害的安全问题之一的SQL注入保护需要加强。此外,网络空间还存在许多未知的漏洞和潜在威胁。在这种情况下,基于结构多样性的主动防御可以发挥有效的作用,防止黑客利用已知或未知的漏洞。并在结构多样性的基础上,提出了一种改进的方法,即异构语言,在数据存储层结合异构数据库,建立了一种主动的数据安全防御模型。我们根据经验评估该漏洞的影响,并通过测试准确性和性能来得出结论,表明我们的安全模型不会遭受与不受保护的漏洞相同的漏洞。最后,讨论了今后的工作和研究方向。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号