天堂国产午夜亚洲专区-少妇人妻综合久久蜜臀-国产成人户外露出视频在线-国产91传媒一区二区三区

常見WEB攻擊方法及其安全防范策略的研究

發(fā)布時間:2017-12-27 15:15

  本文關鍵詞:常見WEB攻擊方法及其安全防范策略的研究 出處:《南昌航空大學》2017年碩士論文 論文類型:學位論文


  更多相關文章: WEB服務安全 WEB服務攻擊 XSS攻擊防護 Connection Flood攻擊防護 SQL注入攻擊防護 模擬攻擊實驗


【摘要】:WEB服務安全是信息安全研究領域的重點之一。在近幾年的信息安全領域中,WEB服務攻擊的次數或流量幾乎成幾何倍增長。而且攻擊WEB服務的范圍也越來越大,從最開始的一般的門戶網站到后來的金融服務或大型的電子商務平臺等都遭受了不同程度的攻擊。為應對這種WEB服務攻擊,企業(yè)或公司被迫采購相關的防火墻或者安全產品設備,但由于安防軟件或設備價格高昂,對有安全需求的公司或企業(yè)來說是他們無力承擔的,而且這種安全防護軟件或設備一般情況下需要廠商維護升級,而客戶所擁有的權限有限,不能夠直接進行維護,通常情況下是在出現問題后才會有人處理;谏鲜鰡栴},該課題研究常見的WEB服務攻擊,并提供一些基本的集成解決方案。主要完成的工作有以下幾點:首先,設計實驗環(huán)境。由于WEB服務攻擊的多樣性,而且每種攻擊的特性也各不相同,所需的研究或實驗環(huán)境也不同,因此,在課題的研究過程中,針對不同的WEB服務攻擊搭建不同的模擬實驗環(huán)境,供測試實驗。實驗的主要研究對象為XSS攻擊防護、Connection Flood攻擊防護及SQL注入攻擊防護。其次,根據不同的攻擊方式設計不同的防范策略。1、提出新的解決方案應對XSS攻擊,主要針對原有或廠商提供的解決方案的缺陷進行完善,提高防護系統(tǒng)的可維護性,使得管理員能夠自己進行維護升級本地的敏感字符庫;設計中斷機制,先響應服務,再處理危險字符,并設計頁面標簽,防止字符回顯帶來的擴展攻擊。2、針對Connection Flood攻擊提供一些輕型的解決方案,可供WEB開發(fā)人員或者系統(tǒng)維護人員便捷的集成到系統(tǒng)當中,應對一般的DDOS攻擊。根據Connection Flood的攻擊特性,設計具有針對性的防護方案,并實現主要的防護功能。3、SQL注入攻擊在近些年中,對WEB服務的威脅尤為嚴重,在課題的研究中,設計SQL專用過濾字符功能函數,并給出具體的應用實例,研究中所涉及的主要內容是完善SQL在執(zhí)行前的一些必要防護操作。最后,實驗驗證策略的有效性。搭建模擬的WEB服務,將具體的研究對象分別集成到WEB服務中,并將WEB服務部署到相關的服務器上。模擬攻擊實驗時對其進行相關的模擬攻擊,記錄不同階段的實驗數據,方便后期的實驗數據分析,以此為依據分析防護系統(tǒng)的可靠性或穩(wěn)定性。
[Abstract]:WEB service security is one of the key points in the field of information security research. In the field of information security in recent years, the number or flow of WEB service attacks has grown almost geometrically. And the scope of attacking WEB services is also increasing. From the beginning of the general portals to the later financial services or the large-scale e-commerce platform, it has been attacked to varying degrees. To deal with this WEB service attacks, enterprises or companies are forced to purchase the firewall security products or equipment, but because of the high security software or equipment prices, they are unable to bear on the security needs of the company or enterprise, and this kind of security software or equipment under normal circumstances require manufacturers to upgrade, and customers the authority is limited, can not be directly maintained, as is usually the case in the problems would have been treated. Based on the above problems, the subject studies the common WEB service attacks and provides some basic integrated solutions. The main tasks are as follows: first, design the experimental environment. Due to the diversity of WEB services attacks and the characteristics of each attack, the required research or experimental environment is also different. Therefore, in the course of research, different simulation environment for different WEB services attacks is built for testing experiments. The main research object of the experiment is XSS attack protection, Connection Flood attack protection and SQL injection attack protection. Secondly, different strategies are designed according to different modes of attack. 1, put forward a new solution to XSS attacks, defect solutions mainly for the original or provided by the manufacturer to improve, improve the protection system maintainability, enables administrators to maintain and upgrade their own local sensitive character library; design of interrupt mechanism, first response service, and handling of dangerous characters, and the design of page label to prevent, extended attack brought significant character. 2, provide some lightweight solutions for Connection Flood attacks, which can be easily integrated into the system by WEB developers or system maintainers, so as to cope with general DDOS attacks. According to the attack characteristics of Connection Flood, the designed protection scheme is designed, and the main protection function is realized. 3, in recent years, SQL injection attack is particularly threatening to WEB services. In the research of this subject, we design SQL specific filter function function, and give specific application examples. The main content of the research is to improve SQL's necessary protection exercises before execution. Finally, the experiment verifies the effectiveness of the strategy. Build a simulated WEB service, integrate specific research objects into WEB services, and deploy WEB services to the related servers. Simulation attack experiments are carried out to simulate related attacks, record the experimental data at different stages, facilitate the analysis of experimental data in the later stage, and analyze the reliability or stability of the protection system based on this.
【學位授予單位】:南昌航空大學
【學位級別】:碩士
【學位授予年份】:2017
【分類號】:TP393.08

【相似文獻】

相關期刊論文 前10條

1 孟偉;張t,

本文編號:1342227


資料下載
論文發(fā)表

本文鏈接:http://sikaile.net/shoufeilunwen/xixikjs/1342227.html


Copyright(c)文論論文網All Rights Reserved | 網站地圖 |

版權申明:資料由用戶55da5***提供,本站僅收錄摘要或目錄,作者需要刪除請E-mail郵箱bigeng88@qq.com
国产一区二区精品高清免费| 黄色在线免费高清观看| 欧美日韩中国性生活视频| 人妻巨大乳一二三区麻豆| 国产白丝粉嫩av在线免费观看| 国产精品欧美日韩中文字幕| 国产精品一区二区香蕉视频| 伊人久久五月天综合网| 日本久久精品在线观看| 亚洲欧美日韩在线中文字幕| 一区二区三区日韩在线| 制服丝袜美腿美女一区二区| 欧美黑人在线精品极品| 日本大学生精油按摩在线观看| 日韩精品成区中文字幕| 搡老熟女老女人一区二区| 玩弄人妻少妇一区二区桃花| 欧美亚洲国产日韩一区二区| 午夜精品在线观看视频午夜| 国产一区二区三区不卡| 国产一区二区三区四区中文| 亚洲av成人一区二区三区在线| 日韩一本不卡在线观看| 国产二级一级内射视频播放| 日本精品视频一二三区| 男人和女人黄 色大片| 欧美有码黄片免费在线视频| 殴美女美女大码性淫生活在线播放| 欧美日韩人妻中文一区二区| 免费观看潮喷到高潮大叫| 亚洲欧洲日韩综合二区| 免费特黄欧美亚洲黄片| 欧美亚洲三级视频在线观看| 91人妻人澡人人爽人人精品| 69久久精品亚洲一区二区| 国产美女精品人人做人人爽| 精品女同一区二区三区| 九七人妻一区二区三区| 日韩在线视频精品视频| 国产日韩在线一二三区| 好吊日在线视频免费观看|