通过检测和保护机制减轻web漏洞,实现安全的web访问

K. Vijayalakshmi, A. Leema
{"title":"通过检测和保护机制减轻web漏洞,实现安全的web访问","authors":"K. Vijayalakshmi, A. Leema","doi":"10.1109/ICSCN.2017.8085652","DOIUrl":null,"url":null,"abstract":"Web Application Security is a serious issue like network security and it cannot be neglected. In the last few decades the world have seen an unprecedented period of technological growth and information access. Unfortunately, along with the technological growth the threats have also increased and the awareness and readiness to deal with them have not kept pace. According to the latest revision of OWASP on July 15, 2016, the top most three web attacks are Injection, Broken authentication and session management, XSS Attacks i.e., Cross-site scripting attacks. Cross-site scripting attacks are a leading online threat. The aim of this attack is to exploit vulnerabilities in the websites which the victim visits. By compromising legitimate websites with malicious content that can capture keystrokes and record user's login information and password. If the login information and password are captured, then the personal data could be compromised. Cross-Site Scripting is the most common attack that allows the attacker to insert a malevolent code in a web page which is then used to affect the visitors of the browser and then the inserted code steals the sensitive information automatically and embezzles the delicate information. In order to prevent the XSS attack, many solutions have been suggested and most of them used are the filters that cleans the malicious input. But many of these filters do not provide prevention to the emerging attacks. Inspired by this attack, the paper proposes and implements an approach based on Extenuating Web Vulnerability with a detection and protection mechanism for a secure web access. This defending mechanism is an effective solution for extenuating web vulnerability for a secure web access.","PeriodicalId":383458,"journal":{"name":"2017 Fourth International Conference on Signal Processing, Communication and Networking (ICSCN)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-03-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":"{\"title\":\"Extenuating web vulnerability with a detection and protection mechanism for a secure web access\",\"authors\":\"K. Vijayalakshmi, A. Leema\",\"doi\":\"10.1109/ICSCN.2017.8085652\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Web Application Security is a serious issue like network security and it cannot be neglected. In the last few decades the world have seen an unprecedented period of technological growth and information access. Unfortunately, along with the technological growth the threats have also increased and the awareness and readiness to deal with them have not kept pace. According to the latest revision of OWASP on July 15, 2016, the top most three web attacks are Injection, Broken authentication and session management, XSS Attacks i.e., Cross-site scripting attacks. Cross-site scripting attacks are a leading online threat. The aim of this attack is to exploit vulnerabilities in the websites which the victim visits. By compromising legitimate websites with malicious content that can capture keystrokes and record user's login information and password. If the login information and password are captured, then the personal data could be compromised. Cross-Site Scripting is the most common attack that allows the attacker to insert a malevolent code in a web page which is then used to affect the visitors of the browser and then the inserted code steals the sensitive information automatically and embezzles the delicate information. In order to prevent the XSS attack, many solutions have been suggested and most of them used are the filters that cleans the malicious input. But many of these filters do not provide prevention to the emerging attacks. Inspired by this attack, the paper proposes and implements an approach based on Extenuating Web Vulnerability with a detection and protection mechanism for a secure web access. This defending mechanism is an effective solution for extenuating web vulnerability for a secure web access.\",\"PeriodicalId\":383458,\"journal\":{\"name\":\"2017 Fourth International Conference on Signal Processing, Communication and Networking (ICSCN)\",\"volume\":\"1 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2017-03-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"7\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2017 Fourth International Conference on Signal Processing, Communication and Networking (ICSCN)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICSCN.2017.8085652\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 Fourth International Conference on Signal Processing, Communication and Networking (ICSCN)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICSCN.2017.8085652","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7

摘要

Web应用程序安全与网络安全一样,是一个不容忽视的严重问题。在过去的几十年里,世界经历了一个前所未有的技术发展和信息获取的时期。不幸的是,随着技术的发展,威胁也在增加,而应对威胁的意识和准备却没有跟上。根据2016年7月15日OWASP的最新版本,排名前三的web攻击分别是注入攻击、破坏身份验证和会话管理攻击、跨站脚本攻击。跨站点脚本攻击是主要的在线威胁。这种攻击的目的是利用受害者访问的网站中的漏洞。通过使用恶意内容破坏合法网站,可以捕获击键并记录用户的登录信息和密码。如果登录信息和密码被捕获,那么个人数据可能会受到损害。跨站脚本攻击是最常见的一种攻击方式,它允许攻击者在网页中插入恶意代码,然后使用该恶意代码影响浏览器的访问者,然后插入的代码自动窃取敏感信息并盗用敏感信息。为了防止XSS攻击,已经提出了许多解决方案,其中大多数使用的是清除恶意输入的过滤器。但是,这些过滤器中的许多都不能对新出现的攻击提供预防。受此攻击的启发,本文提出并实现了一种基于减轻Web漏洞的方法,并为Web访问提供了检测和保护机制。该防御机制是减轻web漏洞,实现web安全访问的有效解决方案。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Extenuating web vulnerability with a detection and protection mechanism for a secure web access
Web Application Security is a serious issue like network security and it cannot be neglected. In the last few decades the world have seen an unprecedented period of technological growth and information access. Unfortunately, along with the technological growth the threats have also increased and the awareness and readiness to deal with them have not kept pace. According to the latest revision of OWASP on July 15, 2016, the top most three web attacks are Injection, Broken authentication and session management, XSS Attacks i.e., Cross-site scripting attacks. Cross-site scripting attacks are a leading online threat. The aim of this attack is to exploit vulnerabilities in the websites which the victim visits. By compromising legitimate websites with malicious content that can capture keystrokes and record user's login information and password. If the login information and password are captured, then the personal data could be compromised. Cross-Site Scripting is the most common attack that allows the attacker to insert a malevolent code in a web page which is then used to affect the visitors of the browser and then the inserted code steals the sensitive information automatically and embezzles the delicate information. In order to prevent the XSS attack, many solutions have been suggested and most of them used are the filters that cleans the malicious input. But many of these filters do not provide prevention to the emerging attacks. Inspired by this attack, the paper proposes and implements an approach based on Extenuating Web Vulnerability with a detection and protection mechanism for a secure web access. This defending mechanism is an effective solution for extenuating web vulnerability for a secure web access.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Design and implementation of programmable read only memory using reversible decoder on FPGA Literature survey on traffic-based server load balancing using SDN and open flow A survey on ARP cache poisoning and techniques for detection and mitigation Machine condition monitoring using audio signature analysis Robust audio watermarking for monitoring and information embedding
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1