首页> 外文期刊>IEEE Transactions on Knowledge and Data Engineering >Specifying and enforcing application-level Web security policies
【24h】

Specifying and enforcing application-level Web security policies

机译:指定和执行应用程序级Web安全策略

获取原文
获取原文并翻译 | 示例

摘要

Application-level Web security refers to vulnerabilities inherent in the code of a Web-application itself (irrespective of the technologies in which it is implemented or the security of the Web-server/back-end database on which it is built). In the last few months, application-level vulnerabilities have been exploited with serious consequences: Hackers have tricked e-commerce sites into shipping goods for no charge, usernames and passwords have been harvested, and confidential information (such as addresses and credit-card numbers) has been leaked. We investigate new tools and techniques which address the problem of application-level Web security. We 1) describe a scalable structuring mechanism facilitating the abstraction of security policies from large Web-applications developed in heterogeneous multiplatform environments; 2) present a set of tools which assist programmers in developing secure applications which are resilient to a wide range of common attacks; and 3) report results and experience arising from our implementation of these techniques.
机译:应用程序级Web安全性是指Web应用程序本身的代码中固有的漏洞(与实施该应用程序的技术或构建该Web服务器/后端数据库的安全性无关)。在过去的几个月中,利用了应用程序级别的漏洞,并带来了严重的后果:黑客诱骗电子商务网站免费运输货物,收集用户名和密码以及机密信息(例如地址和信用卡号) )已泄漏。我们研究了解决应用程序级Web安全问题的新工具和技术。我们1)描述了一种可扩展的结构化机制,该机制有助于从在异构多平台环境中开发的大型Web应用程序抽象安全策略。 2)提供了一组工具,可帮助程序员开发可抵抗各种常见攻击的安全应用程序;和3)报告由于我们实施这些技术而产生的结果和经验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号