首页> 外文期刊>Mathematical Problems in Engineering >A Protection Mechanism against Malicious HTML and JavaScript Code in Vulnerable Web Applications
【24h】

A Protection Mechanism against Malicious HTML and JavaScript Code in Vulnerable Web Applications

机译:防范易受攻击的Web应用程序中恶意HTML和JavaScript代码的保护机制

获取原文
获取原文并翻译 | 示例

摘要

The high-profile attacks of malicious HTML and JavaScript code have seen a dramatic increase in both awareness and exploitation in recent years. Unfortunately, exiting security mechanisms provide no enough protection. We propose a new protection mechanism named PMHJ based on the support of both web applications and web browsers against malicious HTML and JavaScript code in vulnerable web applications. PMHJ prevents the injection attack of HTML elements with a random attribute value and the node-split attack by an attribute with the hash value of the HTML element. PMHJ ensures the content security in web pages by verifying HTML elements, confining the insecure HTML usages which can be exploited by attackers, and disabling the JavaScript APIs which may incur injection vulnerabilities. PMHJ provides a flexible way to rein the high-risk JavaScript APIs with powerful ability according to the principle of least authority. The PMHJ policy is easy to be deployed into real-world web applications. The test results show that PMHJ has little influence on the run time and code size of web pages.
机译:近年来,恶意HTML和JavaScript代码受到广泛关注,其知名度和利用程度均得到了极大提高。不幸的是,现有的安全机制无法提供足够的保护。我们基于Web应用程序和Web浏览器对脆弱Web应用程序中的恶意HTML和JavaScript代码的支持,提出了一种名为PMHJ的新保护机制。 PMHJ防止具有随机属性值的HTML元素的注入攻击和具有HTML元素的哈希值的属性的节点分裂攻击。 PMHJ通过验证HTML元素,限制攻击者可以利用的不安全HTML使用以及禁用可能引起注入漏洞的JavaScript API,来确保网页中的内容安全。根据最小权限原则,PMHJ提供了一种灵活的方式来控制具有强大功能的高风险JavaScript API。 PMHJ策略易于部署到实际的Web应用程序中。测试结果表明,PMHJ对网页的运行时间和代码大小几乎没有影响。

著录项

  • 来源
    《Mathematical Problems in Engineering》 |2016年第4期|7107042.1-7107042.14|共14页
  • 作者单位

    State Key Lab Math Engn & Adv Comp, Zhengzhou 450001, Peoples R China;

    State Key Lab Math Engn & Adv Comp, Zhengzhou 450001, Peoples R China;

    State Key Lab Math Engn & Adv Comp, Zhengzhou 450001, Peoples R China;

    State Key Lab Math Engn & Adv Comp, Zhengzhou 450001, Peoples R China;

    State Key Lab Math Engn & Adv Comp, Zhengzhou 450001, Peoples R China;

    State Key Lab Math Engn & Adv Comp, Zhengzhou 450001, Peoples R China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号