期刊文献+

基于AOP的Web应用程序的安全会话管理 被引量:1

Secure Session Management of Web-Based Application Using Aspect-Oriented Programming
下载PDF
导出
摘要 为降低Web应用程序中合法用户身份被非法窃取的风险,同时提高应用系统机密性及完整性,提出了一种基于AOP的安全会话管理方法。该方法关联远程IP地址与会话标识符(SessionID),通过对访问请求的关联性分析验证合法用户身份,从而应对Web应用程序中常见的失效身份验证与会话管理问题。通过方面(Aspect)封装的应用程序接口(API)具有较好的可扩展性,经编织后的Web应用程序无需修改原业务逻辑代码,就能有效提升自身会话管理机制的安全性及可靠性,保障用户数据不遭受未授权访问。 To reduce the risk of illegally spoofing legitimate users in web applications and improve the confidentiality and integrity of the application,a method of secure session management using Aspect-orientedprogramming(AOP)was proposed. By associating the remote IP address with the session identifier(SessionID)and analyzing the relevance of access requests,the legitimate user's identity was authenticated,so problems ofthe common broken authentication and session management in Web applications were solved. Applicationprogramming interface(API)encapsulated by Aspect has good scalability. The woven web application withoutmodifying the original business logic code can effectively improve the security and reliability of its own session management mechanism,and protect the user data from unauthorized access.
作者 叶志鹏 何成万 张峥峰 YE Zhipeng;HE Chenwan;ZHANG Zhengfeng(School of Computer Science and Engineering,Wuhan Institute of Technology,Wuhan 430205,China)
出处 《武汉工程大学学报》 CAS 2018年第5期565-568,共4页 Journal of Wuhan Institute of Technology
关键词 应用程序接口 面向方面编程 会话固定 失效的身份验证与会话管理 application programming interface aspect-oriented programming session fixation broken authentication and session management
  • 相关文献

参考文献4

二级参考文献30

  • 1张建华,李涛,刘晓洁,徐春林,张楠.Web页面加密存储及访问机制[J].计算机工程,2004,30(13):97-98. 被引量:6
  • 2李海鹰,程灏,吕志强,庄镇泉.针对ARP攻击的网络防御模式设计与实现[J].计算机工程,2005,31(5):170-171. 被引量:47
  • 3张建华,李涛,张楠.Web页面防篡改及防重放机制[J].计算机应用,2006,26(2):327-328. 被引量:13
  • 4吉治钢.基于验证码破解的HTTP攻击原理与防范[J].计算机工程,2006,32(20):170-172. 被引量:20
  • 5ABOBA B, BLUNK L, VOLLBRECHT J, et al. IETF RFC 3748, Extensible Authentication Protocol (EAP) [S]. Reston: IETF, 2004.
  • 6WANG L, SRINIVASAN B, BHATTACHAP, JEE N. Security analysis and improvements on WLANs [J]. Journal of Networks, 2011, 6(3): 470 -481.
  • 7IEEE-SA. IEEE Std 802.1X-2001, port-based network access control [S]. Washington, DC: IEEE Computer Society, 2001.
  • 8TURAB N, MOLDOVE F. A comparison between wireless LAN security protocols [J]. Eleetrieal Engineering and Computer Science, 2009, 71(1): 61-80.
  • 9LEI J, FU X M, HOGREF D, et al. Comparative studies on authentication and key exchange methods for 802. 11 wireless LAN [J]. Computers and Security, 2007, 26(5): 401-409.
  • 10DANTU R, CLOTHIER G, ATRI A. EAP methods for wireless networks [J]. Computer Standards and Interfaces, 2007, 29(3): 289 - 301.

共引文献27

同被引文献6

引证文献1

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部