Back to Search
Start Over
Context-oriented web application protection model
- Source :
- Applied Mathematics and Computation. 285:59-78
- Publication Year :
- 2016
- Publisher :
- Elsevier BV, 2016.
-
Abstract
- Due to growing user demand, web application development is becoming increasingly complicated. Multiple programming languages along with the complex multi-tier architecture commonly involved in web application development contribute to the probability of programming mistakes. Such mistakes may cause serious security vulnerabilities, which can then be exploited by malicious users. Current classifications include a wide variety of web application vulnerabilities, such as SQL injections, Cross-Site Scripting and File Inclusion. Various different protections exist against attacks associated with these vulnerabilities making it difficult to apply a single universal solution. This paper takes an alternative view of the core root of the vulnerabilities. Based on the discovered common traits, a unified extensible context-based model of web applications is proposed. A concept of context is introduced and different attacks are reformulated in terms of context boundary violation. The proposed model can be used to implement a more universal web application protection suitable against different types of attacks. Refereed/Peer-reviewed
- Subjects :
- medicine.medical_specialty
Web development
Computer science
02 engineering and technology
Web engineering
computer.software_genre
Computer security
0202 electrical engineering, electronic engineering, information engineering
medicine
web application protection
Web application
Mashup
Web application development
context-based protection
business.industry
Applied Mathematics
020206 networking & telecommunications
020207 software engineering
Web application security
Computational Mathematics
web application attacks
business
computer
Web modeling
web application vulnerabilities
Secure coding
Subjects
Details
- ISSN :
- 00963003
- Volume :
- 285
- Database :
- OpenAIRE
- Journal :
- Applied Mathematics and Computation
- Accession number :
- edsair.doi.dedup.....889e7723ef7f7f4e4671408ebfec30a6