首页> 外文OA文献 >Defense Against REST-based Web Service Attacks for Enterprise Systems
【2h】

Defense Against REST-based Web Service Attacks for Enterprise Systems

机译:防御企业系统基于REST的Web服务攻击

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

In recent years, Representational State Transfer or REST-based Web Services have become popular for building Web systems. They have become an integral and critical part of information systems to facilitate and integrate the business processes across the enterprise. However, the simplicity of a REST-based implementation has caused the neglect of its systematic security threat analysis and design. One of the issues of systems built with REST services integration is their susceptibility to JSON input attacks. Such attacks could compromise the integrity of critical data in enterprise business processes. We analyze such a security issue in this paper. Some mechanisms used to secure Web sites and servers, such as encryption via HTTPS, static source code analysis, and input validation, can be integrated to defend against the attack.
机译:近年来,代表性状态转移或基于REST的Web服务已在构建Web系统中流行。它们已成为信息系统不可或缺的关键部分,以促进和集成整个企业的业务流程。但是,基于REST的实现的简单性导致对其系统安全威胁分析和设计的忽视。使用REST服务集成构建的系统的问题之一是它们对JSON输入攻击的敏感性。此类攻击可能会损害企业业务流程中关键数据的完整性。我们在本文中分析了这样的安全性问题。可以集成用于保护Web站点和服务器安全的某些机制,例如通过HTTPS加密,静态源代码分析和输入验证,以防御攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号