欢迎访问行业研究报告数据库

行业分类

当前位置:首页 > 报告详细信息

找到报告 1 篇 当前为第 1 页 共 1

查找和防止脚本注入漏洞的系统技术

Systematic Techniques for Finding and Preventing Script Injection Vulnerabilities
作者:Prateek Saxena 作者单位:University of California, Berkeley 加工时间:2013-11-13 信息来源:EECS 索取原文[167 页]
关键词:应用程序漏洞;新兴防御;第二行防御;脚本注入漏洞;安全
摘 要:Computer users trust web applications to protect their nancial transactions and online identities from attacks by cyber criminals. However, web applications today are riddled with security aws which can compromise the security of their web sessions. In this thesis, we address the problem of automatically nding and preventing script injection vulnerabilities, one of the most prominent classes of web application vulnerabilities at present. Speci cally, this thesis makes three contributions towards addressing script injection vulnerabilities. First, we propose two techniques that together automatically uncover script injection vulnerabilities in client-side JavaScript components of web applications without raising false positives. Second,we empirically study the use of sanitization, which is the predominant defense technique to prevent these attacks today. We expose two new classes of errors in the practical use of sanitization in shipping web applications and demonstrate weaknesses of emerging defenses employed in widely used web application frameworks. Third, we propose a type-based approach to automatically perform correct sanitization for applications authored in emerging web application frameworks. Finally, we propose a conceptual framework for a sanitizationfree defense against script injection vulnerabilities, which can form a robust second line of defense.
© 2016 武汉世讯达文化传播有限责任公司 版权所有 技术支持:武汉中网维优
客服中心

QQ咨询


点击这里给我发消息 客服员


电话咨询


027-87841330


微信公众号




展开客服