首页> 外文期刊>Journal of automation and information sciences >Methods of Blocking Vulnerabilities of XSS Type Based on the Service Oriented Architecture
【24h】

Methods of Blocking Vulnerabilities of XSS Type Based on the Service Oriented Architecture

机译:基于面向服务的架构阻断XSS类型漏洞的方法

获取原文
获取原文并翻译 | 示例

摘要

Web-applications are developed in several languages and deployed in various operating systems. This is connected with the various functions that web-application provides to its users. E-commerce applications must take into account various interfaces required for interoperability, security, and availability of a web-applications. Therefore, applications are developed using various languages such as PHP, ASP, JSP, NET, Python, etc., based on web-application requirements. Applications are constantly checked for vulnerabilities, and when they are vulnerable, they can be attacked. Research data shows that about 70% of web-applications are vulnerable to attacks of XSS form. This is due to the fact that entering data by users is allowed in text fields in web-application forms. This increases the threat to a web-application, allowing hackers the embedding of malicious content into the web-application. This article presents a new solution for blocking Cross-Site Scripting (XSS) attacks, which does not depend on the languages, in which web-applications are developed and eliminates XSS vulnerabilities arising from other interfaces. The solution is directed on providing independent services with specific interfaces that can be invoked to perform their tasks in a standard way without prior knowledge of the calling application by the service and without the application knowing how the service actually performs its tasks. The solution is based on a service-oriented architecture (SOA) approach. A method has been developed for blocking vulnerabilities of the XSS type based on the ability to protect applications from XSS attacks using XML and XSD. This includes creating an XML-document based on all form controls submitted by the user.
机译:Web应用程序以多种语言开发并在各种操作系统中部署。这与Web应用程序提供给其用户的各种功能连接。电子商务应用程序必须考虑Web-Applications互操作性,安全性和可用性所需的各种接口。因此,基于Web应用要求,使用各种语言(如PHP,ASP,JSP,NET,Python等)开发了应用程序。应用程序不断检查漏洞,当它们易受攻击时,它们可能会受到攻击。研究数据显示,大约70%的Web应用程序易受XSS形式的攻击。这是由于在Web应用程序表单中的文本字段中允许用户输入数据。这会使对Web应用程序的威胁增加,允许黑客将恶意内容嵌入到Web应用程序中。本文介绍了阻止跨站点脚本(XSS)攻击的新解决方案,该攻击不依赖于语言,其中开发了Web应用程序并消除了其他接口引起的XSS漏洞。该解决方案旨在提供具有特定接口的独立服务,该特定界面可以调用以以标准方式执行其任务,而无需通过服务的呼叫应用程序的先验知识,并且没有应用程序知道服务如何实际执行其任务。该解决方案基于面向服务的架构(SOA)方法。已经开发了一种方法,用于阻止XSS类型的漏洞,基于使用XML和XSD保护来自XSS攻击的应用程序的能力。这包括基于用户提交的所有表单控件创建XML文档。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号