信息网络安全 ›› 2016, Vol. 16 ›› Issue (9): 208-212.doi: 10.3969/j.issn.1671-1122.2016.09.041

• • 上一篇    下一篇

基于Web的软件安全分析与监测

季玉香(), 朱延, 唐晓强   

  1. 国网冀北电力有限公司技能培训中心,河北保定071000
  • 收稿日期:2016-07-25 出版日期:2016-09-20 发布日期:2020-05-13
  • 作者简介:

    作者简介: 季玉香(1981—),女,河北,助教,本科,主要研究方向为计算机应用技术;朱延(1980—),男,河北,经济师,本科,主要研究方向为计算机应用技术;唐晓强(1980—),男,内蒙古,讲师,硕士,主要研究方向为计算机软件技术。

Security Analysis of Web Based Software

Yuxiang JI(), Yan ZHU, Xiaoqiang TANG   

  1. State Grid Jibei Electric Power Company Limited Skills Training Center, Baoding Hebei 071000, China
  • Received:2016-07-25 Online:2016-09-20 Published:2020-05-13

摘要:

基于Web的软件在应用中,由于Web结构的问题安全问题越来越严峻。文章对基于Web的系统结构,从安全角度分析了常见的系统问题,主要针对Web平台的认证、授权、加密及管理等方面的设置环节和常见Web攻击的场景及攻击方式对建立Web安全防御机制的需要,通过特征匹配和分块检索技术对系统进行实时监测,提供信息过滤的技术保护。文章提出了采用分片检索技术设计Web防火墙的方式和运用Simhash算法获取报文特征来提升网络防御能力。经过对Web防火墙的设计与分析,以有效的安全手段阻止了危险的侵害,并且最终通过实验证明了文章设计的安全结构的合理性和可操作性。

关键词: Web安全, 本体特征匹配, 监测防护

Abstract:

Security problem of Web software is more and more serious because of Web structure in its application. This paper analyzed common problems of Web system from the point of view of security. It established security defense mechanism towards Web platform authentication, authorization, encryption and management,carried out real-time monitoring through feature matching and block retrieval technology, providing technique protection for information filtering. Concretely,the method of designing the Web firewall by using the slice retrieval technique and the use of the Simhash algorithm to obtain the message feature to improve the network defense capability were adopted. Through the design and analysis of the Web firewall, danger of infringement can be prevented effectively and finally proved rationality and operability of security structure designed in this paper.

Key words: Web security, feature matching, monitoring and defense

中图分类号: