首页> 外国专利> WEB SERVER/WEB APPLICATION SERVER SECURITY MANAGEMENT APPARATUS AND METHOD

WEB SERVER/WEB APPLICATION SERVER SECURITY MANAGEMENT APPARATUS AND METHOD

机译:Web服务器/ Web应用服务器安全管理装置和方法

摘要

A security management apparatus and method for a web server/web application server is provided. The security management apparatus includes a connection state table storage unit for, as a web client accesses a web server/web application server, storing connection state information, an access time, and a connection policy. A connection state information inspection unit inspects whether current connection state information is present in connection state information of the connection state table storage unit in which the connection policy is set to blocking. If current connection state information is not present, a web session reuse attack determination unit determines whether a current connection is a web session reuse attack. If the current connection is not the web session reuse attack, an attack pattern analysis unit analyzes whether an attack pattern is present. A blocking unit blocks a connection between the web client and the web server/web application server.
机译:提供了一种用于Web服务器/ Web应用服务器的安全管理装置和方法。该安全管理设备包括连接状态表存储单元,用于在网络客户端访问网络服务器/网络应用服务器时存储连接状态信息,访问时间和连接策略。连接状态信息检查单元检查在连接策略被设置为阻塞的连接状态表存储单元的连接状态信息中是否存在当前连接状态信息。如果不存在当前连接状态信息,则Web会话重用攻击确定单元确定当前连接是否是Web会话重用攻击。如果当前连接不是Web会话重用攻击,则攻击模式分析单元分析是否存在攻击模式。阻止单元阻止Web客户端与Web服务器/ Web应用程序服务器之间的连接。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号