首页> 外文会议>World Congress on Internet Security >Root cause analysis of session management and broken authentication vulnerabilities
【24h】

Root cause analysis of session management and broken authentication vulnerabilities

机译:会话管理和破坏的身份验证漏洞的根本原因分析

获取原文
获取原文并翻译 | 示例

摘要

While there are numerous approaches to secure web applications as one of the most prevalent ways to harness the potential of the Internet, attackers almost daily come up with new attempts to exploit various vulnerabilities and compromise data found on the Net. One of the possible venues to attain sustainable solutions is to follow strategic approaches based on detailed analysis and understanding of problems rather than some of the common tactical and often reactive methods. The aim of the paper is to explore employment of Root Cause Analysis (RCA) in session management and broken authentication vulnerabilities and how it can be utilized to improve some security aspects of web applications. By employing RCA, we were able to identify 11 root causes of session management vulnerabilities and 9 root causes of broken authentication vulnerabilities. In addition, the approach provided a detailed, almost macroscopic, view of the vulnerabilities, which consequently led to effective solutions that can minimize the recurrence of attacks on web applications.
机译:尽管有许多方法可以保护Web应用程序安全,这是利用Internet潜力的最普遍方法之一,但是攻击者几乎每天都提出新的尝试来利用各种漏洞并破坏网上发现的数据。获得可持续解决方案的可能场所之一是遵循基于对问题的详细分析和理解的战略方法,而不是某些常见的战术方法和通常是被动方法。本文的目的是探讨在会话管理和破坏的身份验证漏洞中使用根本原因分析(RCA),以及如何利用它来改善Web应用程序的某些安全性。通过使用RCA,我们能够确定11个会话管理漏洞的根本原因和9个身份验证漏洞的根本原因。另外,该方法提供了有关漏洞的详细,几乎宏观的视图,因此可以找到有效的解决方案,可以最大程度地减少对Web应用程序的攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号