首页> 外文学位 >Moving Target Defense for Web Applications
【24h】

Moving Target Defense for Web Applications

机译:Web应用程序的移动目标防御

获取原文
获取原文并翻译 | 示例

摘要

Web applications continue to remain as the most popular method of interaction for businesses over the Internet. With it's simplicity of use and management, they often function as the "front door" for many companies. As such, they are a critical component of the security ecosystem as vulnerabilities present in these systems could potentially allow malicious users access to sensitive business and personal data.;The inherent nature of web applications enables anyone to access them anytime and anywhere, this includes any malicious actors looking to exploit vulnerabilities present in the web application. In addition, the static configurations of these web applications enables attackers the opportunity to perform reconnaissance at their leisure, increasing their success rate by allowing them time to discover information on the system. On the other hand, defenders are often at a disadvantage as they do not have the same temporal opportunity that attackers possess in order to perform counter-reconnaissance. Lastly, the unchanging nature of web applications results in undiscovered vulnerabilities to remain open for exploitation, requiring developers to adopt a reactive approach that is often delayed or to anticipate and prepare for all possible attacks which is often cost-prohibitive.;Moving Target Defense (MTD) seeks to remove the attackers' advantage by reducing the information asymmetry between the attacker and defender. This research explores the concept of MTD and the various methods of applying MTD to secure Web Applications. In particular, MTD concepts are applied to web applications by implementing an automated application diversifier that aims to mitigate specific classes of web application vulnerabilities and exploits. Evaluation is done using two open source web applications to determine the effectiveness of the MTD implementation. Though developed for the chosen applications, the automation process can be customized to fit a variety of applications.
机译:Web应用程序仍然是Internet上最流行的企业交互方式。由于使用和管理简单,它们通常充当许多公司的“前门”。因此,它们是安全生态系统的重要组成部分,因为这些系统中存在的漏洞可能潜在地使恶意用户访问敏感的业务和个人数据。Web应用程序的固有特性使任何人都可以随时随地访问它们,包括任何恶意攻击者,希望利用Web应用程序中存在的漏洞。此外,这些Web应用程序的静态配置使攻击者有机会在闲暇时进行侦察,并通过允许他们有时间在系统上发现信息来提高其成功率。另一方面,防御者通常处于劣势,因为他们没有攻击者为进行反侦察而拥有的同等时机。最后,Web应用程序的不变性质导致未发现的漏洞仍可供开发利用,要求开发人员采用通常会被延迟的反应性方法,或者预测并为所有可能的攻击做好准备,而这些攻击通常是成本高昂的。 MTD)试图通过减少攻击者与防御者之间的信息不对称来消除攻击者的优势。这项研究探讨了MTD的概念以及将MTD应用于安全Web应用程序的各种方法。尤其是,通过实现旨在减轻Web应用程序漏洞和利用的特定类别的自动化应用程序多样化程序,MTD概念可应用于Web应用程序。使用两个开源Web应用程序进行评估,以确定MTD实施的有效性。尽管是针对所选应用开发的,但可以定制自动化过程以适合各种应用。

著录项

  • 作者

    Taguinod, Marthony.;

  • 作者单位

    Arizona State University.;

  • 授予单位 Arizona State University.;
  • 学科 Computer science.;Information technology.
  • 学位 M.S.
  • 年度 2018
  • 页码 66 p.
  • 总页数 66
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号