首页> 外文OA文献 >An investigation into server-side static and dynamic web content survivability using a web content verification and recovery (WVCR) system
【2h】

An investigation into server-side static and dynamic web content survivability using a web content verification and recovery (WVCR) system

机译:使用Web内容验证和恢复(WVCR)系统调查服务器端静态和动态Web内容的可生存性

摘要

A malicious web content manipulation software can be used to tamper with any type of web content (e.g., text, images, video, audio and objects), and as a result, organisations are vulnerable to data loss. In addition, several security incident reports from emergency response teams such as CERT and AusCERT clearly demonstrate that the available security mechanisms have not made system break-ins impossible. Therefore, ensuring web content integrity against unauthorised tampering has become a major issue. This thesis investigates the survivability of server-side static and dynamic web content using the Web Content Verification and Recovery (WCVR) system. We have developed a novel security system architecture which provides mechanisms to address known security issues such as violation of data integrity that arise in tampering attacks. We propose a real-time web security framework consisting of a number of components that can be used to verify the server-side static and dynamic web content, and to recover the original web content if the requested web content has been compromised. A conceptual model to extract the client interaction elements, and a strategy to utilise the hashing performance have been formulated in this research work. A prototype of the solution has been implemented and experimental studies have been carried out to address the security and the performance objectives. The results indicate that the WCVR system can provide a tamper detection, and recovery to server-side static and dynamic web content. We have also shown that overhead for the verification and recovery processes are relatively low and the WCVR system can efficiently and correctly determine if the web content has been tampered with.
机译:恶意的Web内容操纵软件可用于篡改任何类型的Web内容(例如,文本,图像,视频,音频和对象),结果,组织容易受到数据丢失的影响。此外,应急响应小组(如CERT和AusCERT)的一些安全事件报告清楚地表明,可用的安全机制并未使系统无法侵入。因此,确保Web内容的完整性以防止未经授权的篡改已成为一个主要问题。本文使用Web内容验证和恢复(WCVR)系统研究服务器端静态和动态Web内容的可生存性。我们已经开发了一种新颖的安全系统体系结构,该体系结构提供了解决已知安全问题的机制,例如在篡改攻击中出现的违反数据完整性的问题。我们提出了一个实时Web安全框架,该框架由许多组件组成,可用于验证服务器端静态和动态Web内容,并在请求的Web内容遭到破坏时恢复原始Web内容。在这项研究工作中,已经制定了提取客户端交互元素的概念模型和利用哈希性能的策略。解决方案的原型已实施,并已进行实验研究以解决安全性和性能目标。结果表明,WCVR系统可以提供篡改检测功能,并可以恢复服务器端的静态和动态Web内容。我们还显示,验证和恢复过程的开销相对较低,并且WCVR系统可以有效且正确地确定Web内容是否已被篡改。

著录项

  • 作者单位
  • 年度 2008
  • 总页数
  • 原文格式 PDF
  • 正文语种 English
  • 中图分类
  • 入库时间 2022-08-20 21:06:20

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号