Web Application Security

Web Application Security
复制标题

网络应用安全

DOI:
--
复制
发表时间:
2005
期刊:
影响因子:
--
通讯作者:
Nina Ingvaldsen
Nina Ingvaldsen
中科院分区:
--
文献类型:
--
作者:
Julie;Nina Ingvaldsen

文献摘要

被引文献

相似文献

随着越来越多的敏感信息进入基于Web的应用程序,因此可以通过Web浏览器获得这些信息,因此保护这些系统的安全变得越来越重要。可通过Web访问的软件系统持续受到威胁,任何想要尝试入侵的人都可以访问该系统。这些系统不能仅依靠单独的网络区域和防火墙等外部措施来确保安全。Symantecs1互联网安全威胁报告[34]每六个月发布一次。最近发表的一项研究的主要发现证明,针对机密信息的威胁有所增加,针对网络应用程序的攻击也越来越多。在2004年最后六个月记录的所有漏洞中,几乎48%是Web应用程序中的漏洞。开发Web应用程序时应该注意的安全原则确实存在。这份报告研究了现有的指导方针,并提供了开发安全Web应用程序的独立指南。这些准则将在信息安全中心(SIS)的主页上公布,网址为www.norsis.no。该报告还介绍了如何使用所提供的安全准则作为参考点来开发Web应用程序。确定并描述了相关的漏洞和威胁。误用案例将各种威胁与特定的系统功能相关联,风险分析会对这些威胁进行排序,以确定哪些威胁是最紧急的。在设计阶段,从风险分析来看,面临高级别威胁的应用领域一直是关注的中心。在实现阶段也是如此,其中一些威胁的对策是在Java平台上提供的。所实现的解决方案可以被其他在该平台上开发应用的人所借鉴。报告得出的结论是,在开发安全系统时,在整个开发过程中使用安全准则是有用的。1赛门铁克与信息安全合作,提供旨在保护和管理IT基础设施的软件、设备和服务[33]。2信息安全中心负责协调与挪威信息和通信技术(信通技术)安全有关的活动。该中心从公司和部门收到关于安全相关事件的报告,并正在努力获取挪威信通技术系统受到威胁的总体印象[30]。
As more and more sensitive information is entering web based applications, and thus are available through a web browser, securing these systems is of increasing importance. A software system accessible through the web is continuously exposed to threats, and is accessible to anyone who would like to attempt a break-in. These systems can not rely on only external measures like separate network zones and firewalls for security. Symantecs1 Internet Security Threat Report [34] is published every six months. Main findings in the last one published prove that there is an increase in threats to confidential information and more attacks aimed at web applications. Almost 48 percent of all vulnerabilities documented the last six months of 2004 were vulnerabilities in web applications. Security principles that one should pay attention to developing web applications do exist. This report have taken a look at existing guidelines, and provided an independent guide to developing secure web applications. These guidelines will be published at the homepage of The Centre for Information Security2 (SIS), www.norsis.no. The report also describes how a web application has been developed using the provided security guidelines as reference points. Relevant vulnerabilities and threats were identified and described. Misuse cases have related the various threats to specific system functionality, and a risk analysis ranks the threats in order to see which ones are most urgent. During the design phase, the application areas exposed to threats with a high rank from the risk analysis, have been at center of attention. This is also the case in the implementation phase, where countermeasures to some of these threats are provided on the Java platform. The implemented solutions can be adapted by others developing applications on this platform. The report comes to the conclusion, that the use of security guidelines throughout the entire development process is useful when developing a secure system. 1Symantec works with information security providing software, appliances and services designed to secure and manage IT infrastructures [33]. 2The Centre for Information Security (SIS) is responsible for coordinating activities related to Information and Communications Technology (ICT) security in Norway. The centre receives reports about security related incidents from companies and departments, and is working on obtaining an overall impression of threats towards Norwegian ICT systems [30].