首页> 外文学位 >A Verification Framework for Access Control in Dynamic Web Applications.
【24h】

A Verification Framework for Access Control in Dynamic Web Applications.

机译:动态Web应用程序中访问控制的验证框架。

获取原文
获取原文并翻译 | 示例

摘要

Current technologies such as anti-virus software programs and network firewalls provide reasonably secure protection at the host and network levels, but not at the application level. When network and host-level entry points are comparatively secure, public interfaces of web applications become the focus of malicious software attacks. In this thesis, we focus on one of most serious web application vulnerabilities, broken access control. Attackers often try to access unauthorized objects and resources other than URL pages in an indirect way; for instance, using indirect access to back-end resources such as databases. The consequences of these attacks can be very destructive, especially when the web application allows administrators to remotely manage users and contents over the web. In such cases, the attackers are not only able to view unauthorized content, but also to take over site administration. To protect against these types of attacks, we have designed and implemented a security analysis framework for dynamic web applications. A reverse engineering process is performed on an existing dynamic web application to extract a role-based access-control security model. A formal analysis is applied on the recovered model to check access-control security properties. This framework can be used to verify that a dynamic web application conforms to access control polices specified by a security engineer. Our framework provides a set of novel techniques for the analysis and modeling of web applications for the purpose of security verification and validation. It is largely language independent, and based on adaptable model recovery which can support a wide range of security analysis tasks.
机译:诸如防病毒软件程序和网络防火墙之类的最新技术在主机和网络级别提供了合理的安全保护,但在应用程序级别则没有。当网络和主机级入口点相对安全时,Web应用程序的公共接口将成为恶意软件攻击的焦点。在本文中,我们重点研究最严重的Web应用程序漏洞之一,即访问控制中断。攻击者经常尝试间接访问URL页面以外的未经授权的对象和资源。例如,使用对后端资源(例如数据库)的间接访问。这些攻击的后果可能非常具有破坏性,尤其是当Web应用程序允许管理员通过Web远程管理用户和内容时。在这种情况下,攻击者不仅可以查看未经授权的内容,而且可以接管站点管理。为了防止此类攻击,我们为动态Web应用程序设计并实现了安全分析框架。在现有动态Web应用程序上执行逆向工程过程,以提取基于角色的访问控制安全模型。对恢复的模型进行形式化分析,以检查访问控制安全性。该框架可用于验证动态Web应用程序是否符合安全工程师指定的访问控制策略。我们的框架为安全性验证和确认的目的提供了一套用于Web应用程序分析和建模的新颖技术。它在很大程度上与语言无关,并且基于可适应的模型恢复,可以支持各种安全分析任务。

著录项

  • 作者

    Alalfi, Manar H.;

  • 作者单位

    Queen's University (Canada).;

  • 授予单位 Queen's University (Canada).;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2010
  • 页码 218 p.
  • 总页数 218
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号