首页> 外文会议>IEEE International Conference on Anti-Counterfeiting, Security and Identification >Improvement in diversify active defense for web application by using language and database heterogeneity
【24h】

Improvement in diversify active defense for web application by using language and database heterogeneity

机译:通过使用语言和数据库异质性改进Web应用程序的多样化主动防御

获取原文

摘要

According to OWASP selected web application Top 10 vulnerabilities in 2013 and 2017, structured query language (SQL) injection is consistently ranked the 1st. Therefore, the protection of SQL injection, which is one of the most prevalent and pernicious security issues, requires strengthening. Furthermore, there are numerous unknown vulnerabilities and potential threats in cyber-space. In this case, the active defense based on structural diversity can play an effective role to prevent the hacker from exploiting known or unknown vulnerabilities. And on the basis of structural diversity, we propose a modified method, heterogeneous language, combined with heterogeneous database in data storage layer, to establish an active defense model for data security. We empirically assess the impact of the vulnerability and conclude by testing the accuracy and performance, showing that our security model can not suffer from the same vulnerability as the unprotected one. Finally, the future work and research direction are discussed.
机译:根据OWASP所选的Web应用程序2013年和2017年的前10个漏洞,结构化查询语言(SQL)注射始终为第1次。因此,保护​​SQL注入,这是最普遍的安全问题之一,需要加强。此外,在网络空间中存在许多未知的漏洞和潜在威胁。在这种情况下,基于结构多样性的主动防御可以起到有效的作用,以防止黑客利用已知或未知的漏洞。在结构多样性的基础上,我们提出了一种修改的方法,异构语言,与数据存储层中的异构数据库相结合,建立数据安全的主动防御模型。我们通过测试准确性和性能来凭经验评估脆弱性和结论的影响,表明我们的安全模型不能遭受与未受保护的漏洞相同的漏洞。最后,讨论了未来的工作和研究方向。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号