作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2010, Vol. 36 ›› Issue (23): 133-135. doi: 10.3969/j.issn.1000-3428.2010.23.044

• 安全技术 • 上一篇    下一篇

Web安全测试中URL参数重写检测框架

陆余良,郭浩   

  1. (解放军电子工程学院网络系, 合肥 230037)
  • 出版日期:2010-12-05 发布日期:2010-12-14
  • 作者简介:陆余良(1964-),男,教授、博士生导师,主研方向:Web数据挖掘,信息安全;郭浩,博士研究生

URL Parameter Rewriting Detection Framework in Web Security Test

LU Yuliang,GUO Hao   

  1. (Department of Network, PLA Electronic Engineering Institute, Hefei 230037, China)
  • Online:2010-12-05 Published:2010-12-14

摘要: Web站点中URL参数重写会对Web安全测试的准确性造成较大影响。针对该问题,设计URL参数重写检测框架,构造多个测试URL并提交请求,通过基于3种差异分析方法的随机URL取样验证策略,识别出URL中的伪路径,从而提取重写规则、并实现URL参数重写检测。应用C#语言实现的URL参数重写检测爬虫验证了该框架的有效性。

关键词: URL参数重写, 差异分析, Web安全测试

Abstract: In Web site, URL parameter rewriting brings an important influence for Web security test. Aiming at this problem, this paper presents a URL parameter rewriting framework. Test URLs are formed based on the original URL and are submitted to the Web server. By a random URL sampling verification policy based on three differential analysis methods, any fake path in the original URL is detected, rewriting rule is retrieved and URLs with parameter rewriting is detected. URL parameter rewriting detection crawler realized by C# language is validated the effectiveness of this framework.

Key words: URL parameter rewriting, differential analysis, Web security test

中图分类号: