期刊文献+

Web客户端数据存储的安全风险分析

Risk analysis of Web client-end data storage
下载PDF
导出
摘要 Web客户端数据是指Web应用在Web客户端保存的数据。其存储机制已经从最初仅存储ID值的Cookies发展到能够保存重要个人信息的客户端数据库。Web客户端数据存储的发展,给Web应用和终端用户都带来了新的安全风险。文章介绍了客户端数据存储的不同技术,分析了客户端数据存储的安全风险,给出了防范这些安全风险的措施和建议。 Web client-end data is a kind of data that is stored in client's terminals by Web application. The storage mechanisms have changed from Cookies that simply store the ID value, to the client-end database that can store important personal information. With the development of client-end data storage, new risks for both Web applications and end users have appeared. In this paper, different technologies available for client-side data storage are described, the risks associated with client-side data storage are analyzed, and the effective countermeasures and suggestions to prevent these risks are given.
作者 杨建强 方磊
出处 《计算机时代》 2012年第12期6-7,10,共3页 Computer Era
关键词 WEB应用 Web客户端数据存储 安全风险 应对策略 Web application Web client-side data storage security risk countermeasure
  • 相关文献

参考文献7

  • 1Boneh, Dan. "Cookie Same Origin Policy."[EB/OL].http://crypto. stanford, edu/cs 142/lectures/10 -cookie -security. pdf, 2009.1.
  • 2Adobe. "Manage, disable Local Shared Objects I Flash Plaper"[EB/ OL].http://kb2.adobe.com/cps/526/52697ee8.html,2011.4.
  • 3Microsoft. "Silverlight Overview."[EB/OL].http://msdn.microsoft. com/en-us/library/bb404700(v=vs. 95).aspx., 2011.1.
  • 4Gears Team."Gears and Security-Gears API-Google Code."[EB/ OL].http://code.google.com/intl/pl/apis/gears/security.html.
  • 5Hickson,lan.Web SQL Database."[EB/OL].http://www.w3.org/ TR/2010/NOTE-webdatabase-20101118/W3C,2010.11.
  • 6褚诚云.Web安全开发:SQL注入攻击和网页挂马[J].程序员,2008(7):102-104. 被引量:5
  • 7Trivero,Alberto."Abusing HTML 5 Structured Client-side Storage." [EB/OL].http://packetstorm.orionhosting.co.uk/papers/general/html5whitepaper.pdf,2008,7,.

二级参考文献4

  • 1.Mass SQL Injection Attack Targets Chinese Web Sites[]..
  • 2.Writing Secure and Hack Resistant Code Part 2[].researchmicrosoftcorn/collaboration/university/ europe/events/dotnetcc/version/Slides/leblancppt.
  • 3.SQL Injection[]..
  • 4.How To:Protect From SQL Injection in ASP.NET[]..

共引文献4

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部