頁籤選單縮合
| 題 名 | Anti-malicious Injection Based on Meta-programs |
|---|---|
| 作 者 | Lin, Jin-cherng; Chen, Jan-min; | 書刊名 | Journal of Computers |
| 卷 期 | 19:1 2008.04[民97.04] |
| 頁 次 | 頁13-21 |
| 分類號 | 312.76 |
| 關鍵詞 | Black box testing; Malicious injection; Input validation; Security gateway; |
| 語 文 | 英文(English) |
| 英文摘要 | Injection attack is a technique to bypass or modify the originally intended functionality of the program by injecting codes into a computer program or system. It is popular in system hacking or cracking to gain information, Privilege escalation or unauthorized access to a system. Many application's security vulnerabilities result from generic injection problems. Examples of such vulnerabilities are SQL injection, Shell injection and Script injection (Cross Site Scripting). Some applications attempt to protect themselves by filtering malicious input data, but it may not be viable to modify the source of such components (either because the code was shipped in binary form or because the license agreement is prohibitive). We have tried to develop a defense mechanism that can automatically generate meta-programs on security gateway to filter malicious injection. The security gateway is allocated in front of application server to eliminate malicious injection vulnerabilities. To verify the efficiency of the mechanism, we create the web sites made up of some Web applications that often contain third-party vulnerable components shipped in binary form. According to the result of these experiments, our defense mechanism has proved itself efficiency. |
本系統中英文摘要資訊取自各篇刊載內容。