【24h】

A New Feature to Secure Web Applications

机译:安全保护Web应用程序的新功能

获取原文

摘要

Web application security is one of essential components of any web-based systems. As becoming popular of the Internet makes many web sites be attacked by many kinds of attacks. So, we have to propose a secure framework for web applications. For this reason, we have to propose a web application framework which not only analyzes the source code implemented by web developers, also it can detects the vulnerabilities in the source code dynamically. Although a lot of research works have already proposed detection methods of vulnerabilities in web application attacks, but those are not fully detected because their methods do not use the information of the web applications. Therefore, we propose a new method which analyzes the source code of a web application, and then modifies it if needed, in addition, our method has a detection method of an application’s vulnerabilities that are difficult to detect by previous methods. According to our implementation and experiments, it is possible to detect actual attacks, which have been considered difficult to detect, against authentication leaks and SQL injection attacks using dynamic queries.
机译:Web应用程序安全性是任何基于Web的系统的基本组件之一。随着互联网的流行使许多网站受到多种攻击的攻击。因此,我们必须为Web应用程序提出安全的框架。因此,我们必须提出一个Web应用程序框架,它不仅分析了Web开发人员实现的源代码,而且它也可以动态地检测源代码中的漏洞。虽然很多研究工作已经提出了Web应用程序攻击中漏洞的检测方法,但是由于它们的方法不使用Web应用程序的信息,因此不完全检测到这些方法。因此,我们提出了一种新方法,该方法分析了Web应用程序的源代码,然后在需要修改它,此外,我们的方法具有难以通过以前的方法检测的应用程序漏洞的检测方法。根据我们的实施和实验,可以检测使用动态查询的认证泄漏和SQL注入攻击难以检测的实际攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号