Dissertation > Excellent graduate degree dissertation topics show
The Key Technologies Research of Web Application Security Development
Author: ShiHuiZhong
Tutor: ChenBo
School: Nanjing Normal University
Course: Applied Computer Technology
Keywords: Web Vulnerabilities Security Threats .NET Security Mechanisms Vulnerability Description Language Security Assessment Tool Penetration Testing Web Security
CLC: TP393.08
Type: Master's thesis
Year: 2011
Downloads: 103
Quote: 1
Read: Download Dissertation
Abstract
|
With the rapid development and popularization of network and its technology, Web applications have been widely applied in Internet and Intranet. As the functionality and interactivity of Web application strengthen continuously, the corresponding Web vulnerabilities and malicious attacks emerged and exposed a trend of exponential growth. All of these lead to the frequent occurrence of various security incidents, which have brought serious threats to personal privacy security, enterprise security and social stability. Therefore, how to ensure the security of Web application has become the widespread focal point in security community.This paper adopts related theory of Security Development Lifecycle (SDL), considering with the perspective of the integrity of Web safety engineering. We studied three key areas of technologies about Web security design, implementation and running test, included survivability Web security threats modeling, Web security function, the general vulnerability description language and Web security testing.This paper summarizes the recent development of Web security technology and security products. We introduce the current research situation and major threats to Web security, and propose a concept of survivability Web security threats modeling, on which the function, characteristic, method, and modeling steps has been analyzed. The corresponding threat modeling use case has been given and implemented by using the appropriate Web security mechanisms provided by the.NET development language. Then we analyze 5 commonly used Web security comprehensive evaluation tools and compare their performance. We also summarize the advantages and disadvantages of these tools. After that, a generic model of Web security evaluation framework has been proposed. Meanwhile, some Web security evaluation indicators and the evaluation management methods are given.For better sharing and compatible with the vulnerability information among the vulnerability database of various security products, we propose a XML-based Web application security Uniform Vulnerability Description Language (UVDL). We also design the structured XML file and the main framework file of UVDL.We finally achieve a UVDL-based Web security penetration testing tool, compare its performance with Web security comprehensive evaluation tools and OVAL-compatible evaluation component. Test results show that this penetration testing tool has the advantage of higher test speed, better sharing and compatible quality. Furthermore, this tool could effective detect the vulnerability in use cases and better protect of the Web application security.
|
Related Dissertations
- Study on key technology of the Web content management system,TP311.52
- Research on the Internal Control about Monetary Fund of Henan Petroleum Subsidiary Company,F275
- A Study of Network Security Assessment Based on Penetration Testing,TP393.08
- Study on Computer Network Penetration Testing,TP393.06
- The Technology of Browser Security Access and Fingerprint Identification,TP393.092
- Research and Implementation of Information Security Strategy in Electric Enterprises,TP393.08
- Research on Security Defense System of NGN,TN915.08
- The Research and Realization of the Active Network Security Authentication Model,TP393.08
- Research and Implementation of the Penitration Testing Scheme Based on Risk Assassment,TP393.08
- Based on campus network security architecture and design,TP393.08
- Design and Implementation of Web Security Analyse System,TP393.08
- Research on Information Security of MES System Based on Web Environment,TP393.08
- Information Risk Asseesment and Application on Financial Corporation,TP399-C2
- Mobile GIS in the application of information security issue in China,TP309
- Defend Mission Management System Web Safety Owing to Communicating by Letter Programming,TP393.08
- Network Security Technology in Campus Network Application and Research,TP393.08
- Enterprise network security research,TP393.08
- Design and Implementation of Network Security Scheme in Chengdu City e-government,TP393.08
- The System of EC Based on WEB in Indoor Decorating Material and Furniture,TP399
- Applied Study of the Web Secure Technology on the Basis of J2EE,TP393.09
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|