摘要
分析Web服务中的过度加密攻击场景、攻击特点以及SOAP消息特征,提出一种基于简单对象访问协议消息(SOAP)消息的过度加密攻击检测算法。通过检测标签ReferenceList的属性个数统计SOAP消息的加密次数,并将统计出的加密次数与预先设定的阈值进行比较,从而判断是否存在过度加密攻击。在.netWSE安全平台下验证了该检测算法的有效性。
This paper analyzes attack scene, attack features of oversized cryptography and Simple Object Access Protocol(SOAP) message feature of oversized cryptography in Web service, and presents an oversized cryptography attack detection algorithm based on SOAP message. Encryption frequency is counted by detecting the number of attribute in the label of ReferenceList. Then, encryption frequency and the predetermined value are compared to determine oversized cryptography is included or not. The validity of detection algorithm is tested on Web service platform of Microsoft .net WSE.
出处
《计算机工程》
CAS
CSCD
北大核心
2010年第22期129-131,共3页
Computer Engineering
基金
国家自然科学基金委员会与中国民用航空局联合基金资助项目(60979011)
天津市自然科学基金资助项目(09JCYBJC02300)
关键词
DOS攻击
简单对象访问协议消息
过度加密攻击
WEB服务
DoS attack
Simple Object Access Protocol(SOAP) message
oversized cryptography attack
Web service