首页> 外文会议>International Conference on Availability, Reliability and Security >Securing Web Applications with Better 'Patches': An Architectural Approach for Systematic Input Validation with Security Patterns
【24h】

Securing Web Applications with Better 'Patches': An Architectural Approach for Systematic Input Validation with Security Patterns

机译:使用更好的“补丁”保护Web应用程序:具有安全模式系统输入验证的架构方法

获取原文

摘要

Some of the most rampant problems in software security originate from improper input validation. This is partly due to ad hoc approaches taken by software developers when dealing with user inputs. Therefore, it is a crucial research question in software security to ask how to effectively apply well-known input validation and sanitization techniques against security attacks exploiting the user input-related weaknesses found in software. This paper examines the current ways of how input validation is conducted in major open-source projects and attempts to confirm the main source of the problem as these ad hoc responses to the input validation-related attacks such as SQL injection and cross-site scripting (XSS) attacks through a case study. In addition, we propose a more systematic software security approach by promoting the adoption of proactive, architectural design-based solutions to move away from the current practice of chronic vulnerability-centric and reactive approaches.
机译:软件安全中的一些最猖獗的问题源自输入验证不当。这部分原因是软件开发人员在处理用户输入时采取的特设方法。因此,它是一种在软件安全中的重要研究问题,以便如何有效地应用于利用软件中发现的用户输入相关的弱点的安全攻击众所周知的输入验证和消毒技术。本文介绍了在主要开源项目中如何进行输入验证的当前方法,并试图确认问题的主要来源,因为这些临时对输入验证相关的攻击等攻击,如SQL注入和跨站点脚本( XSS)通过案例研究攻击。此外,我们通过促进采用积极的架构设计的解决方案提出了更系统的软件安全方法,以远离当前的慢性脆弱和反应方法的目前的实践。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号