首页> 外文会议>IEEE International Conference Pervasive Computing and Communications >On the Automated Creation of Understandable Positive Security Models for Web Applications
【24h】

On the Automated Creation of Understandable Positive Security Models for Web Applications

机译:关于Web应用程序的可理解积极安全模型的自动创建

获取原文

摘要

Web applications pose new security-related challenges since attacks on web applications strongly differ from those on client-server applications. Traditional network-based firewall systems offer no protection against this kind of attacks since they occur on the application-level. The current solution is the manual definition of large sets of filtering rules which should prevent malicious attempts from being successful. We propose a new framework which should avoid this tedious work. The basic idea is the definition of a description language for positive security models taking the particularities of web applications into account. We then present adaptive techniques which employ this description language in order to describe the valid communication to a given web application. The simplicity of the description language allows the easy identification of unintentionally incorporated vulnerabilities. Experiments for several real-world web applications demonstrate the usefulness of the proposed approach.
机译:Web应用程序构成新的安全相关的挑战,因为Web应用程序的攻击与客户端 - 服务器应用程序的攻击非常不同。传统的基于网络的防火墙系统不提供免受这种攻击,因为它们发生在应用程序级别。当前解决方案是大量过滤规则的手动定义,这应该防止恶意尝试成功。我们提出了一个新的框架,应该避免这种繁琐的工作。基本思想是对正面安全模型的描述语言的定义,以考虑Web应用程序的特殊性。然后,我们呈现采用该描述语言的自适应技术,以便将有效的通信描述给给定的Web应用程序。描述语言的简单性允许简单地识别无意中的漏洞。几个真实世界网络应用的实验表明了所提出的方法的有用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号