Design and Implementation of New Data Validation Service (NDVS) Using Semantic Web Technologies in Web Applications

被引:0
作者
Aljawarneh, Shadi [1 ]
Alkhateeb, Faisal [2 ]
机构
[1] Al Isra Private Univ, Fac Sci & Informat Technol, POB 22, Amman 11622, Jordan
[2] Yarmouk Univ, Irbid, Jordan
来源
WORLD CONGRESS ON ENGINEERING 2009, VOLS I AND II | 2009年
关键词
Web application; data integrity; RDFa; web system; ontology; semantic web technologies; data validation; vulnerabilities; SECURITY;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
We have designed a novel server-side data validation service, based upon semantic web technologies to solve the lack of data validation and bypassing validation issues. The NDVS consists of five components: RDFa annotation for elements of web pages, interceptor, RDFa extractor, RDF parser, and data validator. Our solution is implemented as a prototype. In this paper, we have conducted a pilot study to prevent the security vulnerabilities at the application level such as SQL injections. The results of this initial study have shown that the proposed service (NDVS) could provide a high coverage of prevention of security vulnerabilities.
引用
收藏
页码:179 / +
页数:2
相关论文
共 21 条
[1]  
*AC, 2007, WEB APPL WHAT AR THE
[2]  
ALIJAWARNEH S, 2007, ACSF 07
[3]   Saner: Composing static and dynamic analysis to validate sanitization in web applications [J].
Balzarotti, Davide ;
Cova, Marco ;
Felmetsger, Vika ;
Jovanovic, Nenad ;
Kirda, Engin ;
Kruegel, Christopher ;
Vigna, Giovanni .
PROCEEDINGS OF THE 2008 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, 2008, :387-+
[4]  
BASS T, 2007, CEP SOA OPEN EVENT D
[5]  
BEHLING B, 2005, P INF SEC CURR DEV I, P23
[6]   PowerForms: Declarative client-side form field validation [J].
Brabrand C. ;
Møller A. ;
Ricky M. ;
Schwartzbach M.I. .
World Wide Web, 2000, 3 (04) :205-214
[7]  
CARDONE R, 2005, WWW 05, P2125
[8]  
*CERT, 2007, CERT STAT 1988 2006
[9]  
Chen H., 2002, P 9 ACM C COMPUTER C, P235, DOI DOI 10.1145/586110.586142
[10]   Software security and privacy risks in mobile e-commerce [J].
Ghosh, AK ;
Swaminatha, TM .
COMMUNICATIONS OF THE ACM, 2001, 44 (02) :51-57