首页> 外文会议>International Conference on Emerging Security Information, Systems and Technologies >CAVEAT: Facilitating Interactive and Secure Client-Side Validators for Ruby on Rails applications
【24h】

CAVEAT: Facilitating Interactive and Secure Client-Side Validators for Ruby on Rails applications

机译:警告:促进Ruby在Rails应用程序中的交互式和安全客户端验证器

获取原文

摘要

Modern web applications validate user-supplied data in two places: the server (to protect against attacks such as parameter tampering) and the client (to give the user a rich, interactive data-entry experience). However, today's web development frameworks provide little support for ensuring that client- and server-side validation is kept in sync. In this paper, we introduce CAVEAT, a tool that automatically creates client-side input validation for Ruby on Rails applications by analyzing server-side validation routines. The effectiveness of CAVEAT for new applications is demonstrated by developing three custom apps, and its applicability to existing applications is demonstrated by examining 25 open-source applications.
机译:现代Web应用程序在两个地方验证用户提供的数据:服务器(保护诸如参数篡改等攻击)和客户(为用户提供丰富,交互式数据输入体验)。但是,今天的Web开发框架很少支持确保客户端和服务器端验证保持同步。在本文中,我们通过分析服务器端验证例程,引入警告,该工具自动为Rails应用程序创建Ruby的客户端输入验证。通过开发三个自定义应用,通过审查25个开源应用来证明,通过开发三种自定义应用来证明了新应用程序的有效性,并通过检查25个开源应用来证明其对现有应用的适用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号