首页> 外文OA文献 >Beveiliging van het Web aan de client-zijde: tegengaan van bedreigingen bij websessies
【2h】

Beveiliging van het Web aan de client-zijde: tegengaan van bedreigingen bij websessies

机译:客户端的Web端安全性:抵抗来自Web会话的威胁

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。
获取外文期刊封面目录资料

摘要

As the Web has claimed a prominent place in our society and in our daily lives, Web security has become more important than ever, illustrated by the mainstream media coverage of serious Web security incidents. Over the last years, the center of gravity of the Web has shifted towards the client, where the browser has become a full-fledged execution platform for highly dynamic, complex Web applications. Unfortunately, with the rising importance of the client-side execution context, attackers also shifted their focus towards browser-based attacks, and compromises of client devices. Naturally, when the attackers’ focus shifts towards the client, the countermeasures and security policies evolve as well, as illustrated by the numerous autonomous client-side security solutions, and the recently introduced server-driven security policies, that are enforced within the browser.In this dissertation, we elaborate on the evolution from server-side Web applications to the contemporary client-side applications, that offer a different user experience. We explore the underlying concepts of such applications, and illustrate several important attacks that can be executed from the client side. Ultimately, the focus of this dissertation lies with the security of Web sessions and session management mechanisms, an essential feature of every modern Web application. Concretely, we present three autonomous client-side countermeasures that improve the security of currently deployed session management mechanisms. Each of these countermeasures is implemented as a browser add-on, and is thoroughly evaluated. A fourth technical contribution consists of an alternative session management mechanism, that fundamentally eliminates common threats against Web sessions. A thorough evaluation of our prototype implementation shows the benefits of such an approach, as well as the compatibility with the current Web infrastructure. Finally, we report on our experience with developing client-side countermeasures, both during the inception phase, often backed by theoretical approaches, including formal modeling and rigorous security analyses, and during the development phase, resulting in practically deployable solutions, for example as a browser add-on.
机译:随着Web在我们的社会和日常生活中占据重要地位,Web安全比以往任何时候都变得更加重要,主流媒体对严重Web安全事件的报道就说明了这一点。在过去的几年中,Web的重心已转向客户端,在该客户端中,浏览器已成为用于高度动态,复杂的Web应用程序的成熟执行平台。不幸的是,随着客户端执行上下文的重要性不断提高,攻击者还把重点转移到基于浏览器的攻击和客户端设备的攻击上。自然,当攻击者的重点转移到客户端时,对策和安全策略也会随之演变,如浏览器内部强制执行的众多自主客户端安全解决方案和最近推出的服务器驱动的安全策略所说明的那样。在本文中,我们详细介绍了从服务器端Web应用程序到现代客户端应用程序的发展,它提供了不同的用户体验。我们探索了此类应用程序的基本概念,并说明了可以从客户端执行的几种重要攻击。最终,本文的重点在于Web会话的安全性和会话管理机制,这是每个现代Web应用程序的基本功能。具体而言,我们提出了三种自治的客户端对策,它们可以提高当前部署的会话管理机制的安全性。这些对策中的每一个都作为浏览器插件实现,并经过了全面评估。第四项技术贡献包括一种替代的会话管理机制,该机制从根本上消除了针对Web会话的常见威胁。对我们原型实现的全面评估显示了这种方法的好处,以及与当前Web基础结构的兼容性。最后,我们报告在开发客户端对策方面的经验,包括在初始阶段(通常由理论方法(包括形式化建模和严格的安全分析)支持)以及在开发阶段(例如,作为解决方案)浏览器插件。

著录项

  • 作者

    De Ryck Philippe;

  • 作者单位
  • 年度 2014
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号