...
首页> 外文期刊>International journal of information privacy, security and integrity >Request dependency integrity: validating web requests using dependencies in the browser environment
【24h】

Request dependency integrity: validating web requests using dependencies in the browser environment

机译:请求依赖关系完整性:使用浏览器环境中的依赖关系验证Web请求

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Web requests are the cornerstones of modern web applications. As the browser environment evolves with increasing complexity, attackers have various ways in triggering malicious requests to the server. Traditional security solutions, such as HTTP cookies and session IDs, are insufficient in helping the server to distinguish benign web requests from malicious ones. By design, a web application only expects requests to be generated in certain ways in the browser environment. Therefore, the dynamic browser behaviours and static browser environment that a web request depends on are invariant, which we call request dependency integrity. Based on this observation, we propose a comprehensive approach to validating web requests using dependencies in the browser environment. Our approach extracts the dependency of web requests from the browser, representing it in a request dependency graph (RDG). RDG allows web servers to detect malicious requests through enforcing the request dependency integrity, which is applicable to a wide range of malicious-request-based attacks. We develop an end-to-end solution called ClearRequest and build a prototype in the Firefox browser. We demonstrate the effectiveness of ClearRequest in evaluation using several types of malicious-request-based attacks.
机译:Web请求是现代Web应用程序的基石。随着浏览器环境的复杂性不断提高,攻击者可以通过多种方式触发对服务器的恶意请求。传统的安全解决方案(例如HTTP cookie和会话ID)不足以帮助服务器区分良性Web请求和恶意Web请求。通过设计,Web应用程序仅期望在浏览器环境中以某些方式生成请求。因此,Web请求所依赖的动态浏览器行为和静态浏览器环境是不变的,我们称其为请求依赖关系完整性。基于此观察,我们提出了一种使用浏览器环境中的依赖项来验证Web请求的综合方法。我们的方法从浏览器中提取Web请求的依赖关系,并以请求依赖关系图(RDG)表示它。 RDG允许Web服务器通过强制执行请求依赖关系完整性来检测恶意请求,这适用于范围广泛的基于恶意请求的攻击。我们开发了一个名为ClearRequest的端到端解决方案,并在Firefox浏览器中构建了一个原型。我们使用几种类型的基于恶意请求的攻击证明了ClearRequest在评估中的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号