首页> 外文会议>International Conference on High Performance Computing Simulation >A survey on Information Flow Control mechanisms in web applications
【24h】

A survey on Information Flow Control mechanisms in web applications

机译:Web应用中信息流量控制机制调查

获取原文

摘要

Web applications are nowadays ubiquitous channels that provide access to valuable information. However, web application security remains problematic, with Information Leakage, Cross-Site Scripting and SQL-Injection vulnerabilities - which all present threats to information - standing among the most common ones. On the other hand, Information Flow Control is a mature and well-studied area, providing techniques to ensure the confidentiality and integrity of information. Thus, numerous works were made proposing the use of these techniques to improve web application security. This paper provides a survey on some of these works that propose server-side only mechanisms, which operate in association with standard browsers. It also provides a brief overview of the information flow control techniques themselves. At the end, we draw a comparative scenario between the surveyed works, highlighting the environments for which they were designed and the security guarantees they provide, also suggesting directions in which they may evolve.
机译:现在,Web应用程序是无处不在的频道,可以提供对有价值信息的访问。然而,Web应用程序安全性仍然存在问题,具有信息泄漏,跨站点脚本和SQL-Insion漏洞 - 所有这些都存在对最常见的信息的威胁。另一方面,信息流量控制是一个成熟和良好的区域,提供了保证信息机密性和完整性的技术。因此,提出了许多作品提出了使用这些技术来改善Web应用程序安全性。本文对其中一些作品提供了调查,该作品提出了仅与标准浏览器相关联的服务器端的机制。它还简要概述了信息流控制技术本身。最后,我们在受测量的作品之间绘制了一个比较情景,突出了所设计的环境,并提供他们提供的安全保证,也建议他们可能发展的方向。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号