|
With the rapid development of the Internet, the site has become a variety of information, and comprehensive application platform. Especially some of the key functions of the site, such as the site of the government websites, portals, schools and large financial, securities companies. The information on these sites require authoritative, accurate. Website in providing services to the public while also constantly subjected to outlaws and hackers. To tamper web to publish false reactionary information in a variety of attacks, the attack is among the worst. It directly damage the government's image, and even cause damage to businesses and individuals because of false information. In addition, the hackers also by modifying the page, upload malicious code used to carry out other attacks. Computer operating system vulnerabilities, the vulnerability of the Web server after another, leading to the spread of viruses, Trojans and malicious code. Government, portal, as well as major sites need to have a system to prevent the site from being tampered with. In response to these needs, this paper proposes a tamper-proof system for a website security solution to solve these problems. First, we studied a variety of website content protection software, as well as the principle of the various web tamper-resistant software. Including Polling than technology, enhance the files of the operating system driver level protection technology, and the Web server core embedded tamper-resistant module technology. Performance difficult to realize cross-platform, security, compared the advantages and disadvantages of the various technologies and reliability. We chose the Web server core embedded tamper-resistant module as this thesis and direction. This paper presents a set of web pages tamper-resistant system program. The program includes the Publisher, synchronization server, and tamper detection module three parts. First published server to generate a digital watermark on each page and a script file, then upload the page and the script file, together with the digital watermark to a Web server, the synchronization server to accept the file and watermark document will be stored in the specified location, the last anti-tamper detection module for each time the user wants to access the page for authentication. When the page has been tampered with, the digital watermark and the original watermark does not match, the authentication is not passed. The tamper-resistant module background alarm, automatic recovery and been tampered pages. This solves the problem of site security tamper-resistant. This package includes the publishing server, server synchronization, as well as anti-tamper detection module three parts. In this paper, a few parts, from the perspective of technology platforms, software architecture, detailed design. And in accordance with the design and implementation of Windows, Linux, HP-UX, Solaris platform synchronization server and anti-tamper detection module, and to achieve the release of the server in the Windows and Linux platforms. The anti-tampering detection module for IIS, Apache, Weblogic, WebSphere, and Tomcat were basically covering the current mainstream operating system and Web server. Finally, in practice the system is verified. Good performance through functional testing and stress testing, to achieve the design requirements. Showed good safety and stability of system in operation, and in practice been verified and improved.
|