【24h】

SECURING WEBSITES: A SOFTWARE ENGINEERING APPROACH

机译:保护网站:软件工程方法

获取原文

摘要

Most Web applications are designed in an ad-hoc manner. Despite the widespread use of firewalls and other security solutions, there are obvious holes in the overall security of many web sites. The application itself often provides a point of access for hackers to launch attacks and thus acts like a Trojan horse. A new generation of security solutions is now needed. CERT Coordination Centre suggests that in this era of open, highly distributed, complex systems and vulnerabilities abound and adequate security, using "Defensive Measures" alone, can never be guaranteed. As with all other aspects of crime and conflict, deterrence plays an essential role in protecting society. The ability to "Track and Trace Attackers" is crucial. Both of these approaches combat against insecurity on protocol and hardware level. We however propose a "Three Prong Defense" (a new terminology used by us). Our proposal is based on Software Engineering approach. We believe our research work will enhance awareness amongst the people both developers and acquirers to know how software engineering approach can contribute to the security. Our work will strengthen the willingness to say "no" to ad-hoc ism.
机译:大多数Web应用程序都以ad-hoc方式设计。尽管防火墙和其他安全解决方案广泛使用,但许多网站的整体安全性有明显的漏洞。应用程序本身通常提供了对黑客开始发射攻击并因此像特洛伊木马一样行动的程度。现在需要新一代安全解决方案。 Cert协调中心表明,在这个开放,高度分布式,复杂的系统和漏洞中,使用“防御措施”单独使用“防御措施”,从来没有得到保证。与犯罪和冲突的所有其他方面一样,威慑在保护社会方面发挥着重要作用。 “跟踪和跟踪攻击者”的能力至关重要。这两种方法都反对协议和硬件级别的不安全感。然而,我们提出了“三叉防守”(我们使用的新术语)。我们的提案是基于软件工程方法。我们相信我们的研究工作将提高人民开发人员和收购者的认识,以了解软件工程方法如何促成安全。我们的工作将加强对临时ISM的“不”的意愿。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号