首页 | 官方网站   微博 | 高级检索  
     

正则表达式在电子政务客户端校验中的应用
引用本文:王功明,吴华瑞,赵春江,杨宝祝.正则表达式在电子政务客户端校验中的应用[J].计算机工程,2007,33(9):269-271.
作者姓名:王功明  吴华瑞  赵春江  杨宝祝
作者单位:1. 国家农业信息化工程技术研究中心,北京,100089;首都师范大学信息工程学院,北京,100037
2. 国家农业信息化工程技术研究中心,北京,100089
基金项目:国家科技攻关项目 , 科技部农业科技成果转化基金
摘    要:SQL注入技术通过输入带有SQL关键字的语句破坏后台数据库查询语句完整性,进而开展客户端攻击,危害性很强,此外,不合规范的输入数据,也加重系统负担,降低系统可靠性。所以电子政务系统安全性、可靠性亟待提高。正则表达式具有很强的模式匹配功能,可以用来校验各种类型数据。加入正则表达式校验层,扩充传统三层B/S架构至四层后,通过校验客户端输入数据,能够遏制某些客户端攻击,在一定程度上提高电子政务系统安全性、可靠性。在电子政务系统建设中应用该项技术,取得了优良的效果。

关 键 词:电子政务  正则表达式  数据校验  数据锁  SQL注入
文章编号:1000-3428(2007)09-0269-03
修稿时间:2006-07-10

Application of Regular Expressions in Verifying Client of E-Gov
WANG Gongming,WU Huarui,ZHAO Chunjiang,YANG Baozhu.Application of Regular Expressions in Verifying Client of E-Gov[J].Computer Engineering,2007,33(9):269-271.
Authors:WANG Gongming  WU Huarui  ZHAO Chunjiang  YANG Baozhu
Affiliation:1. National Engineering Research Center for Information Technology in Agriculture, Beijing 100089;2. Information Engineering Institute, Capital Normal University, Beijing 100037
Abstract:SQL injection has ferocious harm to E-Gov.It can break integrality of query sentence in background database by inputing some vicious sentences which contain SQL key words.Thereupon,it carries out client attack.Besides,inputing data which isn't accordant with criterion may aggravate burden of system and reduce reliability of system at all.So the security and reliability in E-Gov system desiderates enhancing.The regular expressions have strong ability to match pattern so as to verify various data which has a varity of types.The traditional B/S frame structure can expand from three layers to four layers by adding regular expressions verifying layer.Therefore,clients are kept from being attacked by verifying input data at client.Thus security and reliability in E-Gov system is improved to a certainly level.This technology acquires good effect in the course of application in an E-Gov system.
Keywords:E-Gov  Regular expressions  Data verifying  Data lock  SQL injection
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《计算机工程》浏览原始摘要信息
点击此处可从《计算机工程》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号