首页 | 本学科首页   官方微博 | 高级检索  
     


Wrappers––a mechanism to support state-based authorisation in Web applications
Authors:M. S.   Ehud   
Affiliation:

a Computer Science, Rand Afrikaans University, P.O. Box 524, Auckland Park 2006, South Africa

b Computer Science, Ben-Gurion University, Beer-Sheva 84105, Israel

Abstract:The premises of this paper are (1) security is application dependent because application semantics directly influence proper protection; but (2) applications are generally too complex to be trusted to implement security as specified by the given security policy. These problems are aggravated if the application operates over time and space.

This paper proposes the use of a simple program (a “wrapper”) that has enough knowledge about a specific application’s potential states and the actions that are permissible in each state. Using this knowledge, it is able to filter requests that should not reach an application at a given point.

Keywords:Web security   Application security   Access control   Wrappers   State-based authorisation
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号