• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2016, Vol. 38 ›› Issue (01): 73-77.

• 论文 • 上一篇    下一篇

面向软件攻击面的Web应用安全评估模型研究

张玉凤,楼芳,张历   

  1. (中国工程物理研究院计算机应用研究所,四川 绵阳 621900)
  • 收稿日期:2014-12-09 修回日期:2015-04-08 出版日期:2016-01-25 发布日期:2016-01-25

Security assessment of web applications
based on software attack surface 

ZHANG Yufeng,LOU Fang,ZHANG Li   

  1. (Institute of Computer Application,China Academy of Engineering Physics,Mianyang 621900,China)
  • Received:2014-12-09 Revised:2015-04-08 Online:2016-01-25 Published:2016-01-25

摘要:

Web应用已成为互联网和企事业单位信息管理的主要模式。随着Web应用的普及,攻击者越来越多地利用它的漏洞实现恶意攻击,Web应用的安全评估已成为信息安全研究的热点。结合Web应用的业务逻辑,提出了其相关资源软件攻击面的形式化描述方法,构造了基于软件攻击面的攻击图模型,在此基础上,实现对Web应用的安全评估。本文构造的安全评估模型,在现有的通用漏洞检测模型基础上,引入业务逻辑安全性关联分析,解决了现有检测模型业务逻辑安全检测不足的缺陷,实现了Web应用快速、全面的安全评估。

关键词: Web应用, 软件攻击面, 攻击图, 安全评估

Abstract:

Web applications have become the principal model of the internet and enterprise information management. With their popularity, attackers launch malicious attacks via their vulnerability. Security assessment of web applications is a major information security concern. In this paper, we first discuss the formal description of software attack surface via business logic of web applications, and then construct an attack graph model. On such basis, we realize the security assessment in web applications. Based on   current general vulnerability detection model, the proposed security assessment model introduces correlation analysis of  business logic security. Our proposal overcomes the defects of current testing models of business logic assessment, and achieves fast and comprehensive security assessment of web applications.

Key words: web applications;software attack surface;attack graph;security assessment