首页 | 官方网站   微博 | 高级检索  
     

基于URL智能白名单的Web应用未知威胁阻断技术研究
引用本文:黄长慧,胡光俊,李海威.基于URL智能白名单的Web应用未知威胁阻断技术研究[J].信息网络安全,2021(3):1-6.
作者姓名:黄长慧  胡光俊  李海威
作者单位:公安部第一研究所
摘    要:在网络空间对抗不断加剧的情况下,我国各重要行业单位信息化深度发展过程中建设的大量Web应用系统的安全面临严峻考验,各行业单位防护技术及措施存在不足,急需建立有效技术防护体系。文章提出一种基于URL智能白名单的Web应用未知威胁阻断防护方案,从合规行为角度入手,以访问控制白名单和非合规行为阻断为核心,通过建立业务白名单动态模型、URL访问控制白名单,实现应对Web应用未知威胁的主动防御体系,提升我国重要行业单位Web应用系统安全防护水平。

关 键 词:URL白名单  未知威胁阻断  动态建模

Research on Unknown Threat Blocking Technology of Web Application Based on URL Intelligent Whitelist
HUANG Changhui,HU Guangjun,LI Haiwei.Research on Unknown Threat Blocking Technology of Web Application Based on URL Intelligent Whitelist[J].Netinfo Security,2021(3):1-6.
Authors:HUANG Changhui  HU Guangjun  LI Haiwei
Affiliation:(First Research Institute of the Ministry of Public Security of PRC,Beijing 100048,China)
Abstract:With the increasing confrontation in cyberspace,the security of a large number of Web application systems constructed in the process of information development of important industry units in China is facing severe challenges.Protection technology and measures of various industries are insufficient,and it is urgent to establish effective technical protection system.This paper proposes an unknown threat blocking protection scheme for Web applications based on URL intelligent whitelist.This scheme proceeds from the perspective of compliance behavior,taking access control whitelist and non-compliance behavior blocking as the core.Through building dynamic model of business whitelist and URL access control whitelist,this scheme establishes an active defense system against unknown threats of Web applications which can improve the security protection level of Web application system of important industry units in China.
Keywords:URL whitelist  unknown threat blocking  dynamic modeling
本文献已被 维普 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号