Author Login Editor-in-Chief Peer Review Editor Work Office Work

Computer Engineering ›› 2010, Vol. 36 ›› Issue (23): 133-135. doi: 10.3969/j.issn.1000-3428.2010.23.044

• Networks and Communications • Previous Articles     Next Articles

URL Parameter Rewriting Detection Framework in Web Security Test

LU Yuliang,GUO Hao   

  1. (Department of Network, PLA Electronic Engineering Institute, Hefei 230037, China)
  • Online:2010-12-05 Published:2010-12-14

Web安全测试中URL参数重写检测框架

陆余良,郭浩   

  1. (解放军电子工程学院网络系, 合肥 230037)
  • 作者简介:陆余良(1964-),男,教授、博士生导师,主研方向:Web数据挖掘,信息安全;郭浩,博士研究生

Abstract: In Web site, URL parameter rewriting brings an important influence for Web security test. Aiming at this problem, this paper presents a URL parameter rewriting framework. Test URLs are formed based on the original URL and are submitted to the Web server. By a random URL sampling verification policy based on three differential analysis methods, any fake path in the original URL is detected, rewriting rule is retrieved and URLs with parameter rewriting is detected. URL parameter rewriting detection crawler realized by C# language is validated the effectiveness of this framework.

Key words: URL parameter rewriting, differential analysis, Web security test

摘要: Web站点中URL参数重写会对Web安全测试的准确性造成较大影响。针对该问题,设计URL参数重写检测框架,构造多个测试URL并提交请求,通过基于3种差异分析方法的随机URL取样验证策略,识别出URL中的伪路径,从而提取重写规则、并实现URL参数重写检测。应用C#语言实现的URL参数重写检测爬虫验证了该框架的有效性。

关键词: URL参数重写, 差异分析, Web安全测试

CLC Number: