期刊文献+

基于代理的Cookie保护技术研究

Research of proxy-based Cookie protection technology
下载PDF
导出
摘要 以窃取客户端Cookie为目的的跨站脚本(XSS)攻击,使互联网用户的个人隐私和利益不断遭受侵犯。如何防御XSS攻击,以保障网民和互联网公司的利益,成为亟待解决的问题。针对基于代理的Cookie保护技术进行了研究,设计了基于代理的Cookie保护框架,阐述了框架的基本原理,给出了关键技术的实现方法,并实现了一个基于代理的Cookie保护系统,最后对该保护系统的有效性进行了测试。测试结果表明本系统可对Cookie提供可靠的保护,为跨站防御的研究提供了新的方向。 Cross site script (XSS) vulneralbility attack that aims to steal cookie violates Internet users' privacy and Interests. It is urgent to defend XSS from damaging the interests of netizens and Internet firms. This paper researched the proxy-based Cookie protection technology, designed a proxy-based cookie protection framework, and both basic theories and the realization of key technologies. Then it implemented a proxy-based Cookie protect system. And it carried out validation on the effectiveness of this technology and the result shows that it is robust to protect cookie, and provided a new direction for XSS research.
出处 《计算机应用研究》 CSCD 北大核心 2012年第8期3036-3038,共3页 Application Research of Computers
关键词 小型文本文件 跨站脚本攻击 保护 代理 Cookie XSS protection proxy
  • 相关文献

参考文献8

  • 1JOHNS M, ENGELMANN B, POSEGGA J. XSSDS : server-side de- tection of cross-site scripting attacks [ C ]//Proc of Computer Security Applications Conference. Anaheim: IEEE, 2008 : 335-344.
  • 2GEBRE M T, LHEE K S,HONG M P. A robust defense against con- tent-sniffing XSS attacks [ J ]. Digital Content, Multimedia Tech- nology and its Applications,2010,9( 1 ) :315-320.
  • 3Network Working Group. RFC 2109, HTYP state management mecha- nism[ S]. Washington DC : Internet Society, 1997.
  • 4STEPHEN J, REDDY P, NAIDU D. Prevention of cross site scripting with E-Guard algorithm[ J]. International Journal of Computer Ap- plications,2011,22(5) :30-34.
  • 5VARJABEDIAN R. Bullet proof cookies [ EB/OL ]. ( 2010- 05 ) [ 2011 - 06 ]. http ://www. codeproject, com/KB/aspnet/BulletProof- Cookies. aspx.
  • 6JASON B, ELIE B, DIVIJ G. State of the art : automated black-box Web application vulnerability testing [ J ]. Security and Privacy, 2010,5( 1 ) :332-345.
  • 7ZHOU Y, EVANS D. Why aren' t HTTP-only cookies more widely de- ployed[ C]//Proc of the 4th Web 2.0 Security and Privacy Work- shop. 2010 : 1-5.
  • 8DIERKS T, RESCORLA E. RFC 4346, The transport layer security (TLS) protocol version 1.1 [ S ]. US : IETF, 2006.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部