首页> 外国专利> Techniques for application security

Techniques for application security

机译:应用程序安全技术

摘要

Software developers previously dealt with each security threat by incorporating a corresponding set of code lines into individual web applications, which required significant amount of time and code lines for each security threat and the resulting code was hard to maintain or modify. One aspect of the present invention addresses common security concerns in a standardized and centralized approach. All user requests for web applications are centralized to a single input and validated by a Web Security Filter. Selected layers of validation filters (e.g., ESAPI and AntiSamy) could be sequentially applied to the user requests, and those filters can be individually maintained/modified as discrete modules. Not only is this centralized, holistic approach to application security effective against a majority of malicious attacks, it is also saves a lot of time and costs in code development and maintenance.
机译:以前,软件开发人员通过将一组相应的代码行合并到单独的Web应用程序中来处理每种安全威胁,这需要大量时间和代码行来应对每种安全威胁,并且所得到的代码难以维护或修改。本发明的一方面以标准化和集中化的方法解决了共同的安全问题。所有对Web应用程序的用户请求都集中到一个输入中,并由Web安全筛选器进行验证。验证过滤器的选定层(例如ESAPI和AntiSamy)可以顺序应用于用户请求,并且这些过滤器可以单独维护/修改为离散模块。这种集中的,整体的应用程序安全性方法不仅可以有效地抵御大多数恶意攻击,而且还可以节省大量时间和代码开发和维护成本。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号