透過您的圖書館登入
IP:18.216.230.107
  • 期刊

An Auto-tuning Sanitizing System for Mitigating Injection Flaws

並列摘要


Injection attacks are dangerous and ubiquitous, contributing enormously to some of the most elaborate Web hacks. Enforcing proper input validation is an effective countermeasure to improve injection flaws. Unless a web application has a strong, centralized mechanism for validating all input from HTTP requests, injection flaws are very likely to exist. However, improper constraining rules may induce some detection error. False negatives may render security risks and false positives will cause improper limits of input characters. In this paper, we design an auto-tuning system to help validating input for each vulnerable injection point. A proper validation rule can be automatically generated through an auto-tuning mechanism. The experimental results show that the system can effectively protect against injection attacks and lower false positives while compared with traditional methods.

被引用紀錄


Lin, Y. H. (2010). 多代理人溝通及協同服務機制於異質環境與資源管理 [doctoral dissertation, Tamkang University]. Airiti Library. https://doi.org/10.6846/TKU.2010.00460
葉俊廷(2009)。工作與休閒時段與遊戲時間之研究:以網頁型線上遊戲為例〔碩士論文,國立交通大學〕。華藝線上圖書館。https://doi.org/10.6842/NCTU.2009.01168
Lou, J. K. (2014). 大型社群網絡之模式挖掘:從網絡架構至使用者行為 [doctoral dissertation, National Taiwan University]. Airiti Library. https://doi.org/10.6342/NTU.2014.00763
CHEN, C. M. (2004). 液晶電視前後蓋塑膠模具之開發研究 [master's thesis, Tatung University]. Airiti Library. https://www.airitilibrary.com/Article/Detail?DocID=U0081-0607200917234322

延伸閱讀