浏览全部资源
扫码关注微信
[ "余航(1997- ),男,中国电信股份有限公司研究院工程师,主要研究方向为网络安全、安全攻防" ]
[ "王帅(1979- ),女,中国电信股份有限公司研究院高级工程师,主要研究方向为网络安全、安全攻防" ]
[ "金华敏(1972- ),男,中国电信股份有限公司研究院高级工程师,主要研究方向为IP网、云计算、大数据安全、网络安全" ]
网络出版日期:2020-11,
纸质出版日期:2020-11-20
移动端阅览
余航, 王帅, 金华敏. 基于RASP的Web安全检测方法[J]. 电信科学, 2020,36(11):113-120.
Hang YU, Shuai WANG, Huamin JIN. RASP based Web security detection method[J]. Telecommunications science, 2020, 36(11): 113-120.
余航, 王帅, 金华敏. 基于RASP的Web安全检测方法[J]. 电信科学, 2020,36(11):113-120. DOI: 10.11959/j.issn.1000-0801.2020294.
Hang YU, Shuai WANG, Huamin JIN. RASP based Web security detection method[J]. Telecommunications science, 2020, 36(11): 113-120. DOI: 10.11959/j.issn.1000-0801.2020294.
目前,传统的Web安全检测方法作用于程序输入输出端,不能防范经变形混淆后绕过检测进入程序内部执行的恶意代码,难以满足当前Web应用安全防护新需求。本方法基于对传统数据流监控方法风险的深入分析,结合RASP技术特性,提出了基于RASP的Web安全检测方法,在Web应用程序内部的权限判别函数参数、系统命令执行函数参数、数据库操作函数参数处埋下 RASP 探针,在代码解释器层面实时检测数据流的变化。本方法基于Java语言进行了实现,在实验室证明该方法在准确率和检测时间上优于传统的Web安全检测方法,并在最后分析提出了本方法的部署和应用场景。
At present
the traditional Web security detection methods act on the input and output of the program
which can not prevent malicious code entering the program after being distorted and confused
and it is difficult to meet the new requirements of Web application security protection.Based on the in-depth analysis of the risk of traditional data flow monitoring methods
combined with the technical characteristics of rasp
a Web security detection method based on rasp was proposed.The rasp probe was embedded in the parameters of authority discrimination function
system command execution function and database operation function in Web application
and the change of data flow was detected in real-time at the code interpreter level.This method was implemented based on Java language.It was proved in the laboratory that this method is better than the traditional Web security detection method in accuracy and detection time.Finally
the deployment and application scenarios of this method were analyzed and proposed.
Global runtime application self-protection (RASP) security market to grow at a CAGR of 49.68% during the period 2018-2022 [Z ] . 2018 .
邱若男 , 胡岸琪 , 彭国军 , 等 . 基于 RASP 技术的 Java Web框架漏洞通用检测与定位方案 [J ] . 武汉大学学报(理学版) , 2020 , 66 ( 3 ): 285 - 296 .
QIU R N , HU A Q , PENG G J , et al . General detection and location scheme of Java Web framework vulnerabilities based on RASP technology [J ] . Journal of Wuhan University (Science Edition) , 2020 , 66 ( 3 ): 285 - 296 .
BELLESSORT R , RUELLAN H , OUEDRAOGO N . Method and device for safely executing a Web application in a Web runtime environment:GB2554697 [P ] .2018-04-11.
陈威 , 陈乐然 , 徐小天 , 等 . 基于 Web 应用系统脆弱性的攻击及其防御技术 [J ] . 电信科学 , 2017 , 33 ( Z1 ): 108 - 116 .
CHEN W , CHEN L R , XU X T , et al . Attack and defense technology based on Web application system vulnerability [J ] . Telecommunications Science , 2017 , 33 ( Z1 ): 108 - 116 .
YIN Z X , LI Z F , CAO Y . A Web application runtime application self-protection scheme against script injection attacks [P ] . 2018
林锋 , 徐柳婧 , 陈晓华 , 等 . 一种基于多视角特征融合的Webshell检测方法 [J ] . 电信科学 , 2020 , 36 ( 6 ): 125 - 132 .
LIN F , XU L J , CHEN X H , et al . A Webshell detection method based on multi view feature fusion [J ] . Telecommunications Science , 2020 , 36 ( 6 ): 125 - 132 .
0
浏览量
554
下载量
0
CSCD
关联资源
相关文章
相关作者
相关机构