作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2010, Vol. 36 ›› Issue (12): 184-186. doi: 10.3969/j.issn.1000-3428.2010.12.063

• 安全技术 • 上一篇    下一篇

同源信用引用协议研究

蔡 亮,刘世贤   

  1. (浙江大学人工智能研究所,杭州 310027)
  • 出版日期:2010-06-20 发布日期:2010-06-20
  • 作者简介:蔡 亮(1976-),男,副教授,主研方向:网络安全; 刘世贤,硕士研究生

Research of Same Origin Credited Approval Agreement

CAI Liang , LIU Shi-xian   

  1. (Institute of Artificial Intelligence, Zhejiang University, Hangzhou 310027)
  • Online:2010-06-20 Published:2010-06-20

摘要:

针对Web访问中的安全问题,提出一种阻止跨站脚本攻击和跨站式请求伪造的同源信用引用(SOCA)协议,以Web站点的信 用度为指标,防止从跨域名网站引入恶意资源,从而加强外部引用资源的交流约束。实验结果表明,SOCA协议具有安全性和兼容性。

关键词: 同源信用引用, 信用度, 跨域名网站

Abstract:

Aiming at the security problem of Web access, Same Origin Credited Approval(SOCA) agreement to defend cross-site scripting attacks and cross-stop-request forgery attacks is proposed. Basing on credit standing, it makes innovative use of the credit of the Web site to prevent the browser from including malicious resources of cross-domain sites and strengthens communication constraints. Experimental results show that the SOCA agreement is safe and compatible.

Key words: Same Origin Credited Approval(SOCA), credit standing;, cross-domain site

中图分类号: