节点文献
基于浏览器的跨站攻击防御系统
Cross-Site Against Defense System Based on Browser
【摘要】 提出一种基于客户端,即用户浏览器的防御跨站攻击的思路,首先在用户浏览器编写插件拦截所有的HTTP请求,然后通过分析判断出该请求是不是跨站请求,再由独立的规则服务器向浏览器插件分发规则,借助排除其中允许的跨站请求,那么剩下的跨站请求即可以认为是恶意的、不被允许的跨站伪造请求,然后弹出对话框向用户告警,拦截该HTTP请求。
【Abstract】 Proposes an idea based on client which defenses cross-site attack.First uses browser plugin to stop all HTTP request,then analyses whether the request is cross-site attack or not,then the rule server distributes the independent rules to browser plugin.So the rest of the cross-site request can be considered to be malicious and not allowed cross-site request if we get rid of the allowed request.At last,browser popups dialog box to inform the user and intercepts the HTTP request.
【关键词】 跨站请求伪造攻击;
防御系统;
规则服务器;
浏览器插件;
【Key words】 Cross-Site Request Forgery; Defensive System; Rule Server; BHO(Browser Helper Objects);
【Key words】 Cross-Site Request Forgery; Defensive System; Rule Server; BHO(Browser Helper Objects);
- 【文献出处】 现代计算机(专业版) ,Modern Computer , 编辑部邮箱 ,2011年15期
- 【分类号】TP393.08
- 【下载频次】84