期刊文献+

基于ISAPI的Web安全防护设计与应用 被引量:1

Design and Application of Web Security Based on ISAPI
下载PDF
导出
摘要 随着Web应用的普及,其安全面临着前所未有的挑战。针对Windows平台中广泛使用的IIS服务器,利用ISAPI在Web应用层设计并实现安全防护系统,可对常见的Web攻击,如SQL注入、XSS攻击、Cookies攻击进行防御。实验表明,该安全防护系统可以在一定程度上保护网站的应用层安全,有效提高网站安全性。 With the development of Internet, Web technology is widely deployed in nowadays information systems, the application and popularization of Web make Web security is confronted with hitherto unknown challenge. Web security protection system for the IIS server widely used in Windows platform, employs ISAPI in the application layer to design and implement. It can defense common web attacks, such as SQL injection, XSS attack, and Cookies attack. The results indicated that it can protect the web application layer security, and improve site security as well.
出处 《软件导刊》 2014年第8期134-136,共3页 Software Guide
基金 河南省科技计划项目(142300410108) 河南省教育厅科学技术研究重点项目(14A520056) 南阳师范学院校级项目(QN2013047)
关键词 SQL注入 XSS跨站攻击 Cookies攻击 WEB安全 SQL Injection XSS Attack Cookies Attack Web Security
  • 相关文献

参考文献5

二级参考文献27

  • 1白建坤.W eb服务安全架构研究[J].计算机应用,2005,25(11):2533-2535. 被引量:8
  • 2谢逸,余顺争.基于Web用户浏览行为的统计异常检测[J].软件学报,2007,18(4):967-977. 被引量:42
  • 3[1]Writing an ISAPI Filter,Revision 0.5(DRAFT)[DB/OL].http://www.bnt.com/inetsdk/default.htm.
  • 4William G J, Viegas H J, Orso A. A Classification of SQL Injection Attacks and Countermeasures[C]//Proc. of International Symposium on Secure Software Engineering. Arlington, USA: IEEE Press. 2006.
  • 5Su Zhendong, Wassermann G. The Essence of Command Injection Attacks in Web Applications[C]//Proc. of Annual Symposium on Principles of Programming Languages. Charleston, USA: [s. n.], 2006.
  • 6Stuttard D, Pinto M. The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws[M].北京:人民邮电出版社, 2009.
  • 7Friedl J E F, Mastering Regular Expressions[M].北京:电子工业出版社,2009.
  • 8Wichers D. The top 10 most critical web application security risks[ R]. The Open Web Application Security Project (OWASP), 2010.
  • 9Kirda E, Vigna G, Jovanovic N. Noxes: a client-side solution for mitigating cross-site scripting attacks [ C ] //The 21st Annum ACM Symposium on Applied Computing. New York, USA: ACM, 2006: 330-337.
  • 10Kirda E, Kruegel C, Virgac G. Client-side cross-site scripting protection[ J]. Computers and Security, 2009, 28 (7) : 592-604.

共引文献36

同被引文献3

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部