首页> 外文会议>International Conference for Young Computer Scientists >An Automatic Mechanism for Sanitizing Malicious Injection
【24h】

An Automatic Mechanism for Sanitizing Malicious Injection

机译:消毒恶意注入的自动机制

获取原文

摘要

According to OWASP Top 10 2007, top 1-5 critical Web application security vulnerabilities caused by unchecked input [1]. Unvalidated Input may lead hacker to inject code to bypass or modify the originally intended functionality of the program to gain information, privilege escalation or unauthorized access to a system. Examples of such vulnerabilities are SQL injection, Shell injection and Cross Site Scripting (XSS). Proper input validation is an effective countermeasure to act as a defense against input attacks but it may induce false negative or false positive. We develop a defense system consisting of a testing framework and a sanitizing mechanism on a security gateway. The security gateway is allocated in front of application server to mitigate malicious injection. To verify the efficiency of the sanitizing mechanism, we focus on whether the filter rules have better detection rate to sanitize input data. Among our experiments, different fields may be automatically injected proper validation rules made up of some sub-rules. By means of the mechanism, we reduce false rate and prove that the hybrid method is more ideal than any traditional input handling.
机译:根据OWASP前10名2007,由未选中的输入引起的Top 1-5关键Web应用程序安全漏洞[1]。未经验证的输入可以引导黑客注入代码以绕过或修改程序的最初预期功能,以获得信息,权限升级或未授权对系统的访问。此类漏洞的示例是SQL注入,shell注入和跨站点脚本(XS)。适当的输入验证是一种有效的对策,以作为对输入攻击的防御,但它可能会诱导错误的负面或假阳性。我们开发由安全网关上的测试框架和消毒机制组成的防御系统。安全网关在应用程序服务器前分配以缓解恶意注入。为了验证消毒机制的效率,我们专注于过滤规则是否具有更好的检测率来消毒输入数据。在我们的实验中,可以自动注入由某些子规则的适当验证规则自动注入不同的字段。通过机制,我们降低了假速率并证明了混合方法比任何传统的输入处理更理想。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号