a国产,中文字幕久久波多野结衣AV,欧美粗大猛烈老熟妇,女人av天堂

Web2.0技術(shù)安全性的研究與防范

發(fā)布時間:2019-04-26 07:15
【摘要】:隨著互聯(lián)網(wǎng)的快速發(fā)展,以個人為中心的開放式Web2.0站點開始逐漸占據(jù)各大網(wǎng)站,各種社交網(wǎng)絡(luò)、個人博客、開放式信息-平臺孕育而生。然而新技術(shù)的使用以及Web2.0網(wǎng)站數(shù)量的不斷增長,在為用戶帶來更好的互聯(lián)網(wǎng)體驗時也帶來了新的安全威脅,各種Web蠕蟲、惡意信息利用Web2.0網(wǎng)或站的開放性大肆傳播,嚴(yán)重危害著互聯(lián)網(wǎng)用戶的安全與隱私。因此,對Web2.0技術(shù)的安全性研究與防范具有重大意義。本文首先對Web2.0相關(guān)技術(shù)進(jìn)行了研究與總結(jié)并對這些技術(shù)的安全性進(jìn)行分析,主要包括能極大改善交互體驗的AJAX技術(shù)以及提高信息傳輸速度的HTTP壓縮技術(shù)。對于AJAX技術(shù),首先研究了主要原理,分析其中可能存在的安全隱患并與傳統(tǒng)Webl.0的交互方式進(jìn)行對比,總結(jié)兩者的優(yōu)缺點,結(jié)合目前出現(xiàn)Web攻擊,分析了 XSS、CSRF等多種攻擊基于AJAX技術(shù)的新改變。對于HTTP壓縮技術(shù),首先研究了目前Web常用的幾種壓縮算法,并對利用HTTP壓縮技術(shù)而新產(chǎn)生的Orcale攻擊、Breach攻擊進(jìn)行了研究與分析。經(jīng)過對以上技術(shù)的安全性分析,通過調(diào)研現(xiàn)有的XSS、CSRF防御方法,主要有基于黑白名單的防御方法和基于Token校驗的防御方法,在分析了這些防御的優(yōu)缺點以及新攻擊對這些方法產(chǎn)生威脅的基礎(chǔ)上,本文提出了一種針對Web2.0應(yīng)用的安全防御方案。該方案將基于特征匹配的輸入檢測以及富文本白名單輸出過濾相結(jié)合進(jìn)行XSS攻擊的防御,使用一種可逆加密算法將Token隨機化來防御與Breach攻擊結(jié)合的新型CSRF攻擊。通過實驗數(shù)據(jù)表明,該防御方案能有效的防御Web2.0應(yīng)用中頻繁出現(xiàn)的攻擊,防御效果相比傳統(tǒng)方案更加顯著。
[Abstract]:With the rapid development of the Internet, individual-centered open Web2.0 sites gradually occupy the major websites, various social networks, personal blogs, open information-platform gestation. However, the use of new technologies and the increasing number of Web2.0 websites also bring new security threats to users when they bring a better Internet experience. Various Web worms and malicious information take advantage of the openness of Web2.0 nets or stations to spread extensively. It seriously endangers the security and privacy of Internet users. Therefore, it is of great significance to study and prevent the security of Web2.0 technology. In this paper, Web2.0-related technologies are studied and summarized, and the security of these technologies is analyzed, including AJAX technology, which can greatly improve interactive experience, and HTTP compression technology, which can improve the speed of information transmission. For AJAX technology, the main principle is studied firstly, the possible security hidden danger is analyzed and compared with the traditional Webl.0, the advantages and disadvantages of the two are summarized, and combined with the Web attack at present, the XSS, is analyzed. Many attacks, such as CSRF, are based on new changes in AJAX technology. For HTTP compression technology, this paper first studies several compression algorithms commonly used in Web at present, and studies and analyzes the new Orcale attack and Breach attack which are generated by using HTTP compression technology. Through the security analysis of the above technologies, through the investigation of the existing XSS,CSRF defense methods, there are mainly black-and-white list-based defense methods and Token-based defense methods. Based on the analysis of the advantages and disadvantages of these defenses and the threat of new attacks to these methods, a security defense scheme for Web2.0 applications is proposed in this paper. This scheme combines feature matching-based input detection and rich text white list output filtering to defend against XSS attacks, and uses a reversible encryption algorithm to randomize Token against a new type of CSRF attack combined with Breach attacks. The experimental data show that this defense scheme can effectively defend against the frequent attacks in Web2.0 applications, and the defense effect is more significant than the traditional scheme.
【學(xué)位授予單位】:北京郵電大學(xué)
【學(xué)位級別】:碩士
【學(xué)位授予年份】:2017
【分類號】:TP393.4

【參考文獻(xiàn)】

相關(guān)期刊論文 前10條

1 詹雄;郭昊;張,

本文編號:2465860


資料下載
論文發(fā)表

本文鏈接:http://www.wukwdryxk.cn/guanlilunwen/ydhl/2465860.html


Copyright(c)文論論文網(wǎng)All Rights Reserved | 網(wǎng)站地圖 |

版權(quán)申明:資料由用戶0a7d3***提供,本站僅收錄摘要或目錄,作者需要刪除請E-mail郵箱bigeng88@qq.com
亚洲AV无码片一区二区三区| 五月婷婷综合在线| 国产婷婷色综合AV性色AV | 影音先锋影av色资源网| 高清人人天天夜夜曰狠狠狠狠| 一本之道高清码国色天香| 太深太粗太大太猛太爽了视频| 亚洲精品日韩中文字幕久久久| 通化县| 亚洲欧美一区| 青青草视频app| 99久久综合狠狠综合久久AⅤ| 国产AV综合影院| 麻豆人人妻人人妻人人片AV| 久久久久久精品免费免费麻辣| 亚洲av一区二区| 亚洲AV无码乱码精品国产| 18国产精品白浆在线观看免费| 中文无码一区二区视频在线播放量| www.四虎| 精品少妇一区| 玖玖爱| 人妻av中文字幕一区二区三区為您提供 | 一本一本久久a久久综合精品蜜桃| 欧美综合自拍亚洲综合图| 粉嫩老牛aⅴ一区二区三区| h动漫在线观看| 极品少妇HDXX麻豆HDXX| 五十路亲子中出在线观看| 欧美性猛交xxx嘿人猛交| 国产成人无码aⅴ片在线观看 | 在线观看免费人成视频播放| 无码人妻精品一区二| 国产精品 亚洲 无码 在线| 久久做夜夜爱天天人人揉| 国产第一av| 欧洲激情| 真实国厂老熟女粗口对白aV| 人人玩人人添人人澡欧美| 最新精品国偷自产手机在线 | 亚洲日本VA午夜在线影院|