The Accuracy Sanitizing Methods Based on Injection Point
碩士 === 大同大學 === 資訊工程學系(所) === 97 === Numbers of the programs are poorly written, lacking even the most basic security procedures for handling input data from users. The input validation vulnerability can be detected by many tools but few tools can fix the flaws automatically. The security gateway ca...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2009
|
Online Access: | http://ndltd.ncl.edu.tw/handle/04261143330693282182 |
id |
ndltd-TW-097TTU05392038 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-097TTU053920382016-05-02T04:11:11Z http://ndltd.ncl.edu.tw/handle/04261143330693282182 The Accuracy Sanitizing Methods Based on Injection Point 基於資料注入點的準確過濾方法 Tien-wei Lin 林典蔚 碩士 大同大學 資訊工程學系(所) 97 Numbers of the programs are poorly written, lacking even the most basic security procedures for handling input data from users. The input validation vulnerability can be detected by many tools but few tools can fix the flaws automatically. The security gateway can used to protect vulnerable Web sites immediately but it may induce false recognition through impersonal rule. By means of hybrid analysis and injection test, the Web pages having vulnerability can be listed. Only those in vulnerable list need to be checked completely, so as to mitigate the system load and false positives effectively. Moreover an algorithm based on multilevel strategy is proposed producing individual sanitizing rule automatically for every vulnerable injection point. To meet the aim of automated validation, the hybrid analyzer, the testing framework and the meta-programs are integrated into a sanitizing mechanism after we analyze the data flow. According to the experimental results, the mechanism has been proved to be a more effective scheme than those traditional input handling methods for mitigating malicious injection. Jin-cherng Lin 林金城 2009 學位論文 ; thesis 41 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 大同大學 === 資訊工程學系(所) === 97 === Numbers of the programs are poorly written, lacking even the most basic security procedures for handling input data from users. The input validation vulnerability can be detected by many tools but few tools can fix the flaws automatically. The security gateway can used to protect vulnerable Web sites immediately but it may induce false recognition through impersonal rule. By means of hybrid analysis and injection test, the Web pages having vulnerability can be listed. Only those in vulnerable list need to be checked completely, so as to mitigate the system load and false positives effectively. Moreover an algorithm based on multilevel strategy is proposed producing individual sanitizing rule automatically for every vulnerable injection point. To meet the aim of automated validation, the hybrid analyzer, the testing framework and the meta-programs are integrated into a sanitizing mechanism after we analyze the data flow. According to the experimental results, the mechanism has been proved to be a more effective scheme than those traditional input handling methods for mitigating malicious injection.
|
author2 |
Jin-cherng Lin |
author_facet |
Jin-cherng Lin Tien-wei Lin 林典蔚 |
author |
Tien-wei Lin 林典蔚 |
spellingShingle |
Tien-wei Lin 林典蔚 The Accuracy Sanitizing Methods Based on Injection Point |
author_sort |
Tien-wei Lin |
title |
The Accuracy Sanitizing Methods Based on Injection Point |
title_short |
The Accuracy Sanitizing Methods Based on Injection Point |
title_full |
The Accuracy Sanitizing Methods Based on Injection Point |
title_fullStr |
The Accuracy Sanitizing Methods Based on Injection Point |
title_full_unstemmed |
The Accuracy Sanitizing Methods Based on Injection Point |
title_sort |
accuracy sanitizing methods based on injection point |
publishDate |
2009 |
url |
http://ndltd.ncl.edu.tw/handle/04261143330693282182 |
work_keys_str_mv |
AT tienweilin theaccuracysanitizingmethodsbasedoninjectionpoint AT líndiǎnwèi theaccuracysanitizingmethodsbasedoninjectionpoint AT tienweilin jīyúzīliàozhùrùdiǎndezhǔnquèguòlǜfāngfǎ AT líndiǎnwèi jīyúzīliàozhùrùdiǎndezhǔnquèguòlǜfāngfǎ AT tienweilin accuracysanitizingmethodsbasedoninjectionpoint AT líndiǎnwèi accuracysanitizingmethodsbasedoninjectionpoint |
_version_ |
1718253436126887936 |