首页> 外文学位 >Web-client runtime security system based on dynamic code instrumentation and policy injection.
【24h】

Web-client runtime security system based on dynamic code instrumentation and policy injection.

机译:基于动态代码检测和策略注入的Web客户端运行时安全系统。

获取原文
获取原文并翻译 | 示例

摘要

The volume of web based malware on the Internet keeps rising despite huge investments on web security. JavaScript, the dominant scripting language for web applications, is the primary channel for most of these attacks. In this thesis, we describe research into the design and implementation of new web application protection system based on code instrumentation techniques. This system combines traditional static analysis techniques with a dynamic HTML, CSS and JavaScript code runtime monitoring agent to offer an efficient, easily deployable, policy driven framework for improved user protection. Rewriting and runtime monitoring are based on providing secure equivalents of JavaScript code constructs known to contain insecurities and hence exploitable by malicious web applications. As a demonstration of the practical capabilities of this framework, three case study attacks and empirical analysis of some of its various aspects across 1000 home pages belonging to the most popular web sites on the Internet are presented.;The results from testing the framework shows its potential for protection of web clients from a broad range of security and privacy issues that manifest on the Internet today.
机译:尽管对Web安全进行了大量投资,但Internet上基于Web的恶意软件的数量仍在不断增加。 JavaScript是Web应用程序中占主导地位的脚本语言,是大多数此类攻击的主要渠道。在本文中,我们描述了基于代码检测技术的新型Web应用程序保护系统的设计和实现的研究。该系统将传统的静态分析技术与动态HTML,CSS和JavaScript代码运行时监视代理相结合,以提供有效,易于部署,策略驱动的框架来改善用户保护。重写和运行时监视基于提供与JavaScript代码结构等效的安全性,这些JavaScript代码结构已知包含不安全因素,因此可被恶意Web应用程序利用。为了说明此框架的实际功能,在属于Internet上最流行网站的1000个主页上,进行了三个案例研究攻击并对其某些方面进行了实证分析。具有保护Web客户端免受当今Internet上广泛出现的各种安全和隐私问题的潜力。

著录项

  • 作者

    Ofuonye, Ejike Emmanuel.;

  • 作者单位

    University of Alberta (Canada).;

  • 授予单位 University of Alberta (Canada).;
  • 学科 Engineering Computer.
  • 学位 M.Sc.
  • 年度 2009
  • 页码 94 p.
  • 总页数 94
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 老年病学;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号