The Accuracy Sanitizing Methods Based on Injection Point

碩士 === 大同大學 === 資訊工程學系(所) === 97 === Numbers of the programs are poorly written, lacking even the most basic security procedures for handling input data from users. The input validation vulnerability can be detected by many tools but few tools can fix the flaws automatically. The security gateway ca...

Full description

Bibliographic Details
Main Authors: Tien-wei Lin, 林典蔚
Other Authors: Jin-cherng Lin
Format: Others
Language:zh-TW
Published: 2009
Online Access:http://ndltd.ncl.edu.tw/handle/04261143330693282182
id ndltd-TW-097TTU05392038
record_format oai_dc
spelling ndltd-TW-097TTU053920382016-05-02T04:11:11Z http://ndltd.ncl.edu.tw/handle/04261143330693282182 The Accuracy Sanitizing Methods Based on Injection Point 基於資料注入點的準確過濾方法 Tien-wei Lin 林典蔚 碩士 大同大學 資訊工程學系(所) 97 Numbers of the programs are poorly written, lacking even the most basic security procedures for handling input data from users. The input validation vulnerability can be detected by many tools but few tools can fix the flaws automatically. The security gateway can used to protect vulnerable Web sites immediately but it may induce false recognition through impersonal rule. By means of hybrid analysis and injection test, the Web pages having vulnerability can be listed. Only those in vulnerable list need to be checked completely, so as to mitigate the system load and false positives effectively. Moreover an algorithm based on multilevel strategy is proposed producing individual sanitizing rule automatically for every vulnerable injection point. To meet the aim of automated validation, the hybrid analyzer, the testing framework and the meta-programs are integrated into a sanitizing mechanism after we analyze the data flow. According to the experimental results, the mechanism has been proved to be a more effective scheme than those traditional input handling methods for mitigating malicious injection. Jin-cherng Lin 林金城 2009 學位論文 ; thesis 41 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 大同大學 === 資訊工程學系(所) === 97 === Numbers of the programs are poorly written, lacking even the most basic security procedures for handling input data from users. The input validation vulnerability can be detected by many tools but few tools can fix the flaws automatically. The security gateway can used to protect vulnerable Web sites immediately but it may induce false recognition through impersonal rule. By means of hybrid analysis and injection test, the Web pages having vulnerability can be listed. Only those in vulnerable list need to be checked completely, so as to mitigate the system load and false positives effectively. Moreover an algorithm based on multilevel strategy is proposed producing individual sanitizing rule automatically for every vulnerable injection point. To meet the aim of automated validation, the hybrid analyzer, the testing framework and the meta-programs are integrated into a sanitizing mechanism after we analyze the data flow. According to the experimental results, the mechanism has been proved to be a more effective scheme than those traditional input handling methods for mitigating malicious injection.
author2 Jin-cherng Lin
author_facet Jin-cherng Lin
Tien-wei Lin
林典蔚
author Tien-wei Lin
林典蔚
spellingShingle Tien-wei Lin
林典蔚
The Accuracy Sanitizing Methods Based on Injection Point
author_sort Tien-wei Lin
title The Accuracy Sanitizing Methods Based on Injection Point
title_short The Accuracy Sanitizing Methods Based on Injection Point
title_full The Accuracy Sanitizing Methods Based on Injection Point
title_fullStr The Accuracy Sanitizing Methods Based on Injection Point
title_full_unstemmed The Accuracy Sanitizing Methods Based on Injection Point
title_sort accuracy sanitizing methods based on injection point
publishDate 2009
url http://ndltd.ncl.edu.tw/handle/04261143330693282182
work_keys_str_mv AT tienweilin theaccuracysanitizingmethodsbasedoninjectionpoint
AT líndiǎnwèi theaccuracysanitizingmethodsbasedoninjectionpoint
AT tienweilin jīyúzīliàozhùrùdiǎndezhǔnquèguòlǜfāngfǎ
AT líndiǎnwèi jīyúzīliàozhùrùdiǎndezhǔnquèguòlǜfāngfǎ
AT tienweilin accuracysanitizingmethodsbasedoninjectionpoint
AT líndiǎnwèi accuracysanitizingmethodsbasedoninjectionpoint
_version_ 1718253436126887936