Merchant Web Applications Defense in E-commerce Enviroment

被引:0
作者
Stankovic, Srdjan [1 ]
Simic, Dejan
Nenadovic, Goran [1 ]
机构
[1] Minist Def, Personnel Dept, Belgrade, Serbia
来源
INFORMATION-AN INTERNATIONAL INTERDISCIPLINARY JOURNAL | 2012年 / 15卷 / 08期
关键词
Web application; Xss; Sql injection; e-commerce;
D O I
暂无
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Protection of merchant Web application is a process that requires constant monitoring of security threats as well as looking for solutions in this field. Since protection has moved from the lower layers of OSI models to the application layer and having in mind the fact that 75% of all the attacks are performed at the application layer, special attention should be paid to creation of Web applications. If we take in account the fact that mistakes made by the very programmers influence upon Web application vulnerability with 64%, it is clear that special attention must be paid to writing code, being familiar with threats as well as with already known ways of protection of Web applications. This paper deals with classification and description of the threats directed toward merchant Web applications in e-commerce environment and ways of protection against the threats. Also, this paper presents real Web application defense against Cross-site Scripting and SQL Injection attacks.
引用
收藏
页码:3301 / 3311
页数:11
相关论文
共 14 条
  • [1] [Anonymous], 2009, GUID BUILD SEC WEB A
  • [2] [Anonymous], 2009, WEB APPL FIR
  • [3] [Anonymous], 2004, WEB APPL SEC CONS TH
  • [4] [Anonymous], 2009, IMPR WEB APPL SEC TH
  • [5] [Anonymous], PROT SQL INJ ASP NET
  • [6] [Anonymous], PREV CROSS SIT SCRIP
  • [7] [Anonymous], 2009, WEB APPL SEC STAT PR
  • [8] Grossman Jeremiah., 2009, Whitehat website security statistic report, V7th
  • [9] Huang LJ, 2009, PROCEEDINGS OF INTERNATIONAL SYMPOSIUM ON COMPUTER SCIENCE AND COMPUTATIONAL TECHNOLOGY (ISCSCT 2009), P349
  • [10] Jovicic B., 2006, Computer Science Information Systems, V3, P83