【24h】

SECURING WEBSITES:A SOFTWARE ENGINEERING APPROACH

机译:保护网站:一种软件工程方法

获取原文

摘要

Most Web applications are designed in an ad-hoc manner.Despite the widespread use of firewalls and other securitysolutions, there are obvious holes in the overall security ofmany web sites. The application itself often provides apoint of access for hackers to launch attacks and thus actslike a Trojan horse. A new generation of securitysolutions is now needed. CERT Coordination Centresuggests that in this era of open, highly distributed,complex systems and vulnerabilities abound and adequatesecurity, using “Defensive Measures” alone, can never beguaranteed. As with all other aspects of crime andconflict, deterrence plays an essential role in protectingsociety. The ability to “Track and Trace Attackers” iscrucial. Both of these approaches combat againstinsecurity on protocol and hardware level. We howeverpropose a “Three Prong Defense” (a new terminologyused by us). Our proposal is based on SoftwareEngineering approach. We believe our research work willenhance awareness amongst the people both developersand acquirers to know how software engineeringapproach can contribute to the security. Our work willstrengthen the willingness to say “no” to ad-hoc ism.
机译:大多数Web应用程序都是以临时方式设计的。尽管防火墙和其他安全解决方案的广泛使用,许多网站的整体安全性还是存在明显漏洞。该应用程序本身通常为黑客提供了访问点以发起攻击,因此就像特洛伊木马一样。现在需要新一代的安全解决方案。 CERT协调中心建议,在这样一个开放,高度分散,复杂的系统和漏洞充斥的时代,仅使用“防御措施”就无法保证足够的安全性。与犯罪和冲突的所有其他方面一样,威慑在保护社会方面发挥着至关重要的作用。 “跟踪和追踪攻击者”的能力至关重要。这两种方法都在协议和硬件级别上与不安全性作斗争。但是,我们提出了“三爪防御”(我们使用的新术语)。我们的建议基于SoftwareEngineering方法。我们相信我们的研究工作将增强开发人员和收购方的认识,以了解软件工程方法如何对安全性做出贡献。我们的工作将加强对临时主义说“不”的意愿。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号