Telecommunications Science ›› 2020, Vol. 36 ›› Issue (11): 113-120.doi: 10.11959/j.issn.1000-0801.2020294

• Topic:Information Security • Previous Articles     Next Articles

RASP based Web security detection method

Hang YU,Shuai WANG,Huamin JIN   

  1. Research Institute of China Telecom Co.,Ltd.,Guangzhou 510630,China
  • Revised:2020-11-10 Online:2020-11-20 Published:2020-12-09

Abstract:

At present,the traditional Web security detection methods act on the input and output of the program,which can not prevent malicious code entering the program after being distorted and confused,and it is difficult to meet the new requirements of Web application security protection.Based on the in-depth analysis of the risk of traditional data flow monitoring methods,combined with the technical characteristics of rasp,a Web security detection method based on rasp was proposed.The rasp probe was embedded in the parameters of authority discrimination function,system command execution function and database operation function in Web application,and the change of data flow was detected in real-time at the code interpreter level.This method was implemented based on Java language.It was proved in the laboratory that this method is better than the traditional Web security detection method in accuracy and detection time.Finally,the deployment and application scenarios of this method were analyzed and proposed.

Key words: Web application, network security, RASP, security monitoring

CLC Number: 

No Suggested Reading articles found!