首页> 外文期刊>Data & Knowledge Engineering >Wrappers- a mechanism to support state-based authorisation in Web applications
【24h】

Wrappers- a mechanism to support state-based authorisation in Web applications

机译:包装器-一种支持Web应用程序中基于状态的授权的机制

获取原文
获取原文并翻译 | 示例

摘要

The premises of this paper are (1) security is application dependent because application semantics directly influence proper protection; but (2) applications are generally too complex to be trusted to implement security as specified by the given security policy. These problems are aggravated if the application operates over time and space. This paper proposes the use of a simple program (a "wrapper") that has enough knowledge about a specific application's potential states and the actions that are permissible in each state. Using this knowledge, it is able to filter requests that should not reach an application at a given point.
机译:本文的前提是:(1)安全性取决于应用程序,因为应用程序语义直接影响适当的保护;但是(2)应用程序通常太复杂而无法信任,无法实现给定安全策略所指定的安全性。如果应用程序在时间和空间上运行,则会加剧这些问题。本文提出了使用简单程序(“包装程序”)的方法,该程序对特定应用程序的潜在状态以及每种状态所允许的动作有足够的了解。使用此知识,它可以过滤在给定点不应到达应用程序的请求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号