期刊文献+

Web应用程序客户端恶意代码技术研究与进展 被引量:9

Study and Trends on Client-side Malicious Code of Web Application
下载PDF
导出
摘要 随着Web应用程序特别是Web2.0应用的日益广泛,针对Web应用程序的恶意代码开始大肆传播,成为网络安全的重大威胁。本文首先介绍了目前Web应用程序面临的威胁状况,然后讨论了Web应用程序客户端恶意代码技术以及Web浏览器的漏洞研究和利用技术,最后对Web应用程序客户端恶意代码技术的发展趋势进行了展望,并给出了Web应用程序客户端安全的加固策略。 Web application and in particular Web 2.0 application gains more and more popularity nowadays, while malicious codes are now targeting more at Web application. In this paper, we provide a detailed overview of threats to Web application at first and then turn to the discussion on malicious scripts at the client-side of Web application, which includes the history, variation and upgrade of XSS, JavaScript function hook technology at runtime and the new trends of client-side malicious scripts in the context of Web 2.0 application. The Web browser's vulnerability discovery and exploit related technologies are also introduced. At last, we predict the future development of client-side malicious code of Web application and give some advices on the security enhancements of Web application client-side.
机构地区 北京邮电大学
出处 《电信科学》 北大核心 2009年第2期72-79,共8页 Telecommunications Science
基金 国家"863"计划基金资助项目(No.2007AA01Z466和No.2008AA011004)
关键词 Web应用程序安全 恶意代码 蠕虫 JavaScript恶意代码 XSS CSRF Web浏览器安全 Web application security, malicious code, worm, JavaScript malicious code, XSS, CSRF, Web browser security
  • 相关文献

参考文献19

  • 1Christey S, Martin A R. Vulnerability type distributions in CVE. http://cwe.mitre.org/documents/vuln-trends/index.html#table 1
  • 2Mitigating cross-site scripting with http-Only cookies, http://msdn. microsoft.com/workshop/author/dhtml/httponly_cookies.asp
  • 3SANS top-20 2007 security risks (2007 Annum Update). http:// www.sans.org/top20/#c 1
  • 4The CAPTCHA project telling humans and computers apart, http: //www.captcha.net/
  • 5Phishing with superbait silicon valley chapter, http://www.whitehatsec. com/presentationsJphishing_superbait.pdf
  • 6W3C document object model, http://www.w3.org/DOM/
  • 7Query J. http://jquery.com/
  • 8Reilly O T. What is Web 2.0. http://www.oreilly.com/pub/a/oreilly/ tim/news/2005/09/30/what-is-web-20.html
  • 9http://openkapow.com/.
  • 10http://dodgeit.net/.

同被引文献28

引证文献9

二级引证文献40

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部