首页> 外文学位 >Anticipating and hardening the Web against socio-technical security attacks.
【24h】

Anticipating and hardening the Web against socio-technical security attacks.

机译:预测和加强Web抵御社会技术安全攻击。

获取原文
获取原文并翻译 | 示例

摘要

The Internet, and the World Wide Web in particular, is becoming an increasingly important resource to people in modern society. Mostly, people are browsing the web for news, shopping, blogging, researching, or simply surfing; the vast majority of Internet use is browsing the Web with one of many browsers. To appease users' demand for robust and novel web applications, programmers are discovering new tricks to add unique or novel behavior to their web sites (through asynchronous data fetching, or animations). Though these features are based on mature languages and standards, new security problems are often uncovered with each new trick. Many of these are socio-technical problems: the result of technological nuances in the use of scripting or other web technologies coupled with the way people interact with the web sites. This sociological spin on technical security problems, introducing an element of deception, makes the security of the web more complex and not easily patched with simple software fixes.;The web was not designed with security in mind, only utility. In its evolution from simple html, it has inflated to have a colossal number of technologies and features supported by browsers that have increased the web's potential for misuse. It is time to re-consider fundamental control of web content, and this dissertation shows how to begin. Most security problems with web applications stem from loose control of data; there are no strictly enforced policies that dictate how information can flow between technologies in the web browser or out from a web application's domain. This dissertation investigates the underlying problems in the way data is transfered in and out of browsers and their components by analyzing a variety of security problems and their corresponding solutions. Through presentation and analysis of some cases, underlying themes are exposed that can eventually be used to address web security on a more fundamental level.
机译:互联网,尤其是万维网,正在成为现代社会中人们越来越重要的资源。通常,人们正在浏览网络以查找新闻,购物,博客,研究或只是上网; Internet的绝大多数用途是使用许多浏览器之一浏览Web。为了满足用户对健壮和新颖的Web应用程序的需求,程序员发现了一些新技巧,可以(通过异步数据获取或动画)在其网站上添加独特或新颖的行为。尽管这些功能基于成熟的语言和标准,但每个新技巧通常都会发现新的安全问题。其中许多是社会技术问题:使用脚本或其他Web技术时技术上的细微差别以及人们与网站交互方式的结果。这种对技术安全性问题的社会学思考,引入了一种欺骗手段,使网络的安全性变得更加复杂,并且不容易通过简单的软件修补进行修补。网络设计时并未考虑安全性,而只是考虑实用性。从简单的html演变而来,它膨胀了,获得了众多浏览器支持的技术和功能,从而增加了网络被滥用的可能性。现在该重新考虑对Web内容的基本控制了,该论文展示了如何开始。 Web应用程序的大多数安全问题源于对数据的松散控制。没有严格执行的策略来指示信息如何在Web浏览器中的技术之间流动或从Web应用程序的域中流出。本文通过分析各种安全问题及其对应的解决方案,研究了数据在浏览器及其组件中的进出传输方式中的潜在问题。通过展示和分析某些情况,揭示了潜在的主题,这些主题最终可用于更基本的级别解决Web安全问题。

著录项

  • 作者

    Stamm, Sidney L.;

  • 作者单位

    Indiana University.;

  • 授予单位 Indiana University.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2009
  • 页码 219 p.
  • 总页数 219
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号