Font Size: a A A

Study On The Design And Implementation Of Ring Structure’s Dynamic Webpage Tamper-Proof System

Posted on:2013-04-21Degree:MasterType:Thesis
Country:ChinaCandidate:G Y DuanFull Text:PDF
GTID:2248330395984833Subject:Software engineering
Abstract/Summary:PDF Full Text Request
With the rapid development of information technology, the applications ofInternet bring the convenience and become indispensable in our life. Meanwhile, italso becomes the target of malicious attackers. The current Web server platform lacksof integrity protection mechanism for the page users’ request, but the traditionaltamper-proof system can not ensure its own security; therefore, it’s necessary for us todevelop not only strong self-defense ability but also dynamic webpage tamper-proofsystem.This paper aims to study the dynamic webpage tamper-proof system based on thering structure through the analysis of the existing development of webpagetamper-proof technology, and introduces the contents about three threads andself-protection ability of ring structure technology enhancing system based on theexisted tamper-proof technique. This paper demonstrates the system structure,working mechanism and its realization process.The main characteristics of our systemare as follows.To implement the detection and recovery of dynamic web pages usingmessage digesting with minimal system overhead.To solve the problems after thedefense failure of invasion of a single server.To record attack log and ensure theintegrity of Web pages and the safe execution of servers. The system includes fourmodules: initialization and preprocessing module, self-defense of agent andcommunications module, tamper module and trusted publishing module. Theinitialization and preprocessing module is responsible for the configuration of thesystem parameters and the calculation and storage of digital fingerprints of the filesunder the protection.The core of our system is the self-defense of agent andcommunications module, which is responsible for establishing the trust betweenself-protection agents using three-thread and cyclic polling technique. The tampermodule is responsible for monitoring the integrity of dynamic web pages verifying thelegitimacy of the webpage change, and notifying the occurrence of an attack torecover the altered files in time. The trusted publishing module is responsible for theverification of safe certification and ensures the legitimacy of changes.The experimental results show that,the tamper-proof system based on ringstructure is superior to traditional tamper-proof systems in some aspects such as theagent’s self-defense, tamper detection and recovery of files. Most importantly, the proposed system can ensure website safety without affecting the efficiency of theserver being protected.
Keywords/Search Tags:Ring protection, Tamper-Proof, Three threads, Digital fingerprint
PDF Full Text Request
Related items