论文部分内容阅读
现代Web开发技术诞生及广泛应用,基于Web安全漏洞的各种网络攻击成为网络安全威胁之一。XSS跨站脚本攻击已经算得上是除DDOS攻击和SQL注入攻击之外第三大Web攻击。本文针对XSS跨站攻击开展分析研究,首先介绍XSS跨站攻击的特点、主要类型及攻击原理,结合相关分析阐述了XSS跨站攻击的广泛性及其危害性,总结经典XSS跨站脚本攻击案例;再通过实验室虚拟环境搭建模拟实现XSS跨站攻击过程,分析XSS跨站攻击遗留痕迹,结合公安工作中网络犯罪侦查的业务需要,总结了XSS跨站攻击的痕迹数据并阐述防御此攻击的具体措施。
The birth and widespread application of modern web development technology, various web attacks based on web security vulnerabilities become one of the network security threats. XSS cross-site scripting attacks are already the third largest Web attack in addition to DDOS attacks and SQL injection attacks. This paper analyzes the XSS cross-site attacks, first introduced the characteristics of the XSS cross-site attacks, the main types and principles of attack, combined with related analysis of the XSS cross-site attacks described the extensive and harmful, summarizing the classic XSS cross-site scripting attacks ; Then through the laboratory virtual environment to build a simulation of XSS cross-site attack process, analysis of XSS cross-station attack traces left, combined with the business needs of criminal investigation of public security work, summarizes the XSS cross-site attack trace data and describes the defense against this attack specific measure.