...
首页> 外文期刊>Journal of Computers >An Automated Mechanism for Secure Input Handling
【24h】

An Automated Mechanism for Secure Input Handling

机译:安全输入处理自动机制

获取原文
           

摘要

—Numbers of the programs are poorly written, lacking even the most basic security procedures for handling input data from users. The input validation vulnerability can be detected by many tools but few tools can fix the flaws automatically. The security gateway can used to protect vulnerable Web sites immediately but it may induce false recognition through impersonal rule. By means of hybrid analysis and injection test, the vulnerable Web pages can be listed. Only those in vulnerable list need to be checked completely, so as to mitigate the system load and false positives effectively. Moreover an algorithm based on multilevel strategy is proposed producing individual sanitizing rule automatically for every vulnerable injection point. To meet the aim of automated validation, the enhanced crawler, the testing framework and the metaprograms are integrated into a sanitizing mechanism after we analyze the data flow. According to the experimental results, the mechanism has been proved to be a more effective scheme than those traditional input handling methods for mitigating malicious injection.
机译:-Numbers编写不佳,缺乏用于处理用户输入数据的最基本的安全程序。可以通过许多工具检测到输入验证漏洞,但很少有工具可以自动修复缺陷。安全网关可以使用立即保护易受攻击的网站,但它可能会通过非人格规则引起虚假识别。通过混合分析和注射测试,可以列出易受攻击的网页。只需要完全检查弱势列表中的那些,以便有效地减轻系统负载和误报。此外,基于多级策略的算法是为每个易受攻击点自动产生各个消毒规则。为满足自动验证的目的,在分析数据流后,增强型履带器,测试框架和成分数集成到消​​毒机制中。根据实验结果,已证明该机制是一种比这些传统投入处理方法更有效的方案,用于减轻恶意注射。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号