首页> 外文会议>International Conference on Electronics, Computer and Computation >Towards a Framework of Configuring and Evaluating ModSecurity WAF on Tomcat and Apache Web Servers
【24h】

Towards a Framework of Configuring and Evaluating ModSecurity WAF on Tomcat and Apache Web Servers

机译:迈向在Tomcat和Apache Web服务器上配置和评估ModSecurity WAF的框架

获取原文

摘要

Open-source software has slowly infiltrated the enterprise space because the products tend to be cheaper, flexible, and secure in comparison to propriety products. However, open-source software incurs the cost of beavering to acquire professionals to, customize the product in meeting expectations, support fixes and in extending the product to a wide range of capabilities. ModSecurity is an open-source web application firewall (WAF) developed explicitly for Apache, and technically only listens to HTTP port 80. This study utilized the agility and flexibility property of open-source software to design a framework of configuring Apache module ModSecurity WAF to communicate with Tomcat server (which runs explicitly on HTTP port 8080). Furthermore, using suitable penetration testing methodology, this study investigates and compares the effectiveness of ModSecurity WAF in both Apache and Tomcat environments. ModSecurity WAF limitations were also investigated. In addition to providing a framework for configuring ModSecurity on tomcat server, this study provides an understanding of web application vulnerabilities, the techniques used to exploit them and the mitigation mechanisms to address them.
机译:开源软件已慢慢渗透到企业领域,因为与专有产品相比,这些产品往往更便宜,更灵活且更安全。但是,开源软件会招致海狸的成本,以吸引专业人员来满足期望,定制解决方案以及将产品扩展到广泛的功能,从而对产品进行定制。 ModSecurity是专门为Apache开发的开放源代码Web应用程序防火墙(WAF),从技术上讲,它仅侦听HTTP端口80。该研究利用开放源代码软件的敏捷性和灵活性属性,​​设计了一个配置Apache模块ModSecurity WAF的框架,以与Tomcat服务器(在HTTP端口8080上显式运行)进行通信。此外,使用适当的渗透测试方法,本研究调查并比较了ModSecurity WAF在Apache和Tomcat环境中的有效性。还对ModSecurity WAF限制进行了调查。除了提供用于在tomcat服务器上配置ModSecurity的框架之外,本研究还提供对Web应用程序漏洞,利用这些漏洞的技术以及缓解这些漏洞的缓解机制的理解。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号