期刊文献+

基于面向对象数据库的网站安全研究

Research on Security of Web Site Based on Object-oriented Database
下载PDF
导出
摘要 简要介绍了在网站安全当中具有较大危害性的SQL注入攻击的定义、特点、基本原理、实施步骤,现有防御对策以及这些对策的局限性,面向对象数据库db4o的特点和优势。针对现有对策的局限性结合db4o的优点,提出了一种基于面向对象数据库db4o的全新的对策,对该对策进行了详细的分析,经过实验证明,本对策具有一定的理论和实际意义。 This paper introduces the definition,characteristic,fundamental theory,attack step of SQL injection attacks which have much harm to the websites security;the technology of defense the SQL injection attacks and these technologys limitations;The characteristic and advantages of db4o which is an object-oriented database.In response to these defenses limitations and db4os advantages,the author propose a type of new technology of defense which is based on object-oriented database and by detailed analyzing of this type of new technology proved it has much theoretical and practical significance.
出处 《计算机安全》 2010年第6期62-64,共3页 Network & Computer Security
基金 中南财经政法大学中央高校基本科研业务费资助。项目主持人:屈振新 副教授 1972
关键词 网站安全 SQL注入攻击 面向对象数据库 DB4O Websites security SQL injection attacks Object-oriented databas Db4o
  • 相关文献

参考文献5

  • 1SQLServer安全回顾[EB/OL].http://www.microsoft.com/china/ctc/Newsletter/04/ctc2.htm.
  • 2陈小兵,张汉煜,骆力明,黄河.SQL注入攻击及其防范检测技术研究[J].计算机工程与应用,2007,43(11):150-152. 被引量:72
  • 3Jim Paterson,Stefan Edlich, Henrik H?rning,Reidar H?rning.The definitive guide to db4o[M] .Apress,2006:5.
  • 4Litchfield D .Web application disassembly with ODBC error messages[EB/OL], http ://81. cgisecurity, com/lib/webappdis, doc.
  • 5William R.Cook,Carl Rosenberger. Native queries for persistent objects[J]. Morgan Kaufmann,2006.

二级参考文献9

  • 1张勇,李力,薛倩.Web环境下SQL注入攻击的检测与防御[J].现代电子技术,2004,27(15):103-105. 被引量:55
  • 2徐陋,姚国祥.SQL注入攻击全面预防办法及其应用[J].微计算机信息,2006,22(03X):10-12. 被引量:40
  • 3SQL Server 安全回顾[EB/OL].http://www.microsoft.com/china/ctc/Newsletter/04/ctc2.htm.
  • 4Anley C.Advanced SQL injection in SQL server applications[EB/OL].http://www.creangel.com/papers/advanced_sql_injection.pdf,An NGS Software Insight Security Research (NISR) Publication,2002.
  • 5Litchfield D.Web application disassembly with ODBC error messages[EB/OL].http://81.cgisecurity.com/lib/webappdis.doc.
  • 6Sam M S.NG,SQLBlock:SQL injection protection by variable normalization of SQL statement[EB/OL].http://www.iem.pw.edu.pl/~kozlowk3 / biblioteczka / www_SQL / SQL_Injection_Protection_by_Variable_Normalization_of_SQL_Statement.pdf.
  • 7Geneiatakis D,Kambourakis G,Lambrinoudakis C.SIP message tampering the SQL code injection attack[EB/OL].http://www.snocer.org/Paper/camera-ready_soft_com.pdf.
  • 8Finnigan P.SQL injection and Oracle[EB/OL].[2002-11-21].http://wwworacledevelopernl/newforum/files/2002_11_21%20SecurityFocus%20SQL%20Injection%20and%20Oracle.pdf.
  • 9Cerrudo C.Manipulating Microsoft SQL server using SQL injection[EB/OL].http://injection.rulezz.ru/Manipulating_SQL_Server_Using_SQL_Injection.pdf.

共引文献71

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部