电信科学 ›› 2009, Vol. 1 ›› Issue (2): 72-79.doi: 10.3969/j.issn.1000-0801.2009.02.018

• 专题:网络与信息安全 • 上一篇    下一篇

Web应用程序客户端恶意代码技术研究与进展

黄玮,崔室江,胡正名   

  1. 北京邮电大学 北京 100876
  • 出版日期:2009-02-15 发布日期:2017-08-18
  • 基金资助:
    国家“863”计划基金资助项目;国家“863”计划基金资助项目

Study and Trends on Client-side Malicious Code of Web Application

Wei Huang,Baojiang Cui,Zhengming Hu   

  1. Beijing University of Posts and Telecommunications,Beijing 100876,China
  • Online:2009-02-15 Published:2017-08-18

摘要:

随着Web应用程序特别是Web 2.0应用的日益广泛,针对Web应用程序的恶意代码开始大肆传播,成为网络安全的重大威胁。本文首先介绍了目前Web应用程序面临的威胁状况,然后讨论了Web应用程序客户端恶意代码技术以及Web浏览器的漏洞研究和利用技术,最后对Web应用程序客户端恶意代码技术的发展趋势进行了展望,并给出了Web应用程序客户端安全的加固策略。

关键词: Web应用程序安全, 恶意代码, 蠕虫, JavaScript恶意代码, XSS, CSRF, Web浏览器安全

Abstract:

Web application and in particular Web 2.0 application gains more and more popularity nowadays,while malicious codes are now targeting more at Web application.In this paper,we provide a detailed overview of threats to Web application at first and then turn to the discussion on malicious scripts at the client-side of Web application,which includes the history,variation and upgrade of XSS,JavaScript function hook technology at runtime and the new trends of client-side malicious scripts in the context of Web 2.0 application.The Web browser's vulnerability discovery and exploit related technologies are also introduced.At last,we predict the future development of client-side malicious code of Web application and give some advices on the security enhancements of Web application client-side.

Key words: Web application security, malicious code, worm, JavaScript malicious code, XSS, CSRF, Web browser security

No Suggested Reading articles found!