Web应用程序漏洞检测与防护技术研究
[Abstract]:In recent years, security events caused by Web application vulnerability occur frequently, and Web application vulnerability is more and more serious to network security. Cross-site script (Cross Site Script,XSS (cross-site script vulnerability) vulnerability is the most common Web application vulnerability. Attackers can exploit cross-site scripting vulnerabilities to exploit information theft, session hijacking, phishing spoofing and other attacks. But the existing Web vulnerability detection schemes and tools are generally not perfect, there are many defects such as low efficiency, high miss rate, high false alarm rate and so on. Therefore, the XSS vulnerability detection and defense technology needs to be further in-depth research. Designing a high-performance XSS vulnerability detection system is helpful to prevent cross-site scripting attacks of Web applications and reduce the occurrence of Web security events. Based on the in-depth study on the exploitation process of XSS vulnerability and the existing detection techniques, the requirements of the vulnerability detection system are analyzed in detail, and a cross-station script vulnerability detection system for Web applications is designed and implemented. Based on the existing Web vulnerability detection technology and detection tools, the system adds the function of authentication code recognition, which solves the problem that the data can be submitted to the server only after the authentication code is inputted during the detection period. According to the deficiency of the existing Web vulnerability detection tools, the network crawler of the system is improved, and more XSS codes that can bypass the server filtering are constructed according to the filtering rules of the server to the XSS code. The test results show that the proposed system has low miss detection rate, low false positive rate and high efficiency of the improved network crawler. By adding the authentication code recognition function and constructing the XSS code which can bypass the server filtering rules, the cross-station script vulnerability can be deeply excavated and the miss detection rate of the system can be reduced. An efficient web crawler that can accurately extract the information of page interaction points improves the correctness and efficiency of vulnerability detection.
【学位授予单位】:南京邮电大学
【学位级别】:硕士
【学位授予年份】:2017
【分类号】:TP393.08
【参考文献】
相关期刊论文 前10条
1 莫永华;于冰冰;;二维码中XSS攻击检测系统的设计[J];现代计算机(专业版);2016年24期
2 王岩;程绍银;蒋凡;;自动化检测Android应用反射型跨站脚本漏洞的方法[J];计算机系统应用;2015年07期
3 严磊;丁宾;姚志敏;马勇男;郑涛;;基于MD5去重树的网络爬虫的设计与优化[J];计算机应用与软件;2015年02期
4 杜雷;辛阳;;基于规则库和网络爬虫的漏洞检测技术研究与实现[J];信息网络安全;2014年10期
5 刘奇旭;温涛;闻观行;;Flash跨站脚本漏洞挖掘技术研究[J];计算机研究与发展;2014年07期
6 尹龙;尹东;张荣;王德建;;一种扭曲粘连字符验证码识别方法[J];模式识别与人工智能;2014年03期
7 曹文;郭帆;余敏;张磊;;基于哈希树和有限状态机的XSS检测模型[J];计算机工程;2013年06期
8 陈景峰;王一丁;张玉清;刘奇旭;;存储型XSS攻击向量自动化生成技术[J];中国科学院研究生院学报;2012年06期
9 潘古兵;周彦晖;;基于静态分析和动态检测的XSS漏洞发现[J];计算机科学;2012年S1期
10 颜浩;蒋巍;蒋天发;;SQLI和XSS漏洞检测与防御技术研究[J];信息网络安全;2011年12期
相关会议论文 前1条
1 李楠;谷利泽;钮心忻;;用于XSS扫描的网络爬虫的设计与实现[A];2010年全国通信安全学术会议论文集[C];2010年
相关硕士学位论文 前1条
1 黄俊;基于指令集随机化的XSS检测系统研究[D];中国科学技术大学;2014年
,本文编号:2470807
本文链接:https://www.wllwen.com/guanlilunwen/ydhl/2470807.html