摘要
阐述了浏览器跨协议通信的安全性问题,这类通信是通过将一个目标协议封装进一个载体协议中来完成的.研究表明,在满足协议有足够的容错度和有方法将目标协议封装进载体协议两个前提下,完全独立的两个协议是可以互操作的,潜在的两个不同的协议能够进行命令和数据的通信.因此跨协议通信为攻击者利用载体协议实现对目标协议的攻击提供了新的可能性,主要安全问题诸如跨协议跨站脚本、跨协议特征探测、暴力攻击.
This paper explored the Inter-Protocol Communication and vulnerability. This has been investigated through encapsulating the target protocol within a carrier protocol. Http and Imap example demonstrate that under certain conditions distinct protocols were interoperable. The potential of two different protocols meaningfully communicating commands and data. Therefore Inter-Protocol Communication offers new possibilities for an attacker using a carrier protocol to attack the target protocol,such as Inter-Protocol Cross-site Scripting,Inter-Protocol Fingerprinting,Brute Force Attacks.
出处
《哈尔滨商业大学学报(自然科学版)》
CAS
2017年第4期473-476,共4页
Journal of Harbin University of Commerce:Natural Sciences Edition