首页> 外文会议>ACM SIGSAC Conference on Computer and Communications Security >POSTER - CRYPTSERVER: Strong Data Protection in Commodity LAMP Servers
【24h】

POSTER - CRYPTSERVER: Strong Data Protection in Commodity LAMP Servers

机译:海报 - Cryptserver:商品灯服务器中的强大数据保护

获取原文

摘要

Modern web applications store sensitive data on their servers. Such data is prone to theft resulting from exploits against vulnerabilities in the server software stacks. In this work, we propose a new architecture for web servers, called CRYPTSERVER, in which we pre-determine and fix a small amount of application code that can compute over sensitive data. By encrypting sensitive data before making it available to the rest of untrusted application code, CRYPTSERVER provides strong defense against all malicious code that an attacker may run in the server software stack. As a step towards making this approach practical, we develop an assistance tool to identify the portion of server-side logic that requires computation over sensitive data. Our preliminary results show that the size of such logic is small in six popular web applications we study. To the extent of our evaluation, converting these applications to a CRYPTSERVER architecture requires modest developer effort.
机译:现代Web应用程序在其服务器上存储敏感数据。此类数据易于盗窃从服务器软件堆栈中的漏洞引起的盗窃。在这项工作中,我们为Web服务器提出了一种新的架构,称为CryptServer,其中我们预先确定并修复了可以在敏感数据上计算的少量应用程序代码。通过对敏感数据进行加密,然后可用于其余的不受信任的应用程序代码,Cryptserver为攻击者在服务器软件堆栈中运行的所有恶意代码提供强烈的防御。作为实现这种方法的一步,我们开发了一个辅助工具,以确定需要在敏感数据上计算的服务器端逻辑的部分。我们的初步结果表明,我们学习的六种流行的Web应用中,这种逻辑的大小很小。在我们的评估范围内,将这些应用程序转换为Cryptserver架构需要适度的开发人员努力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号