论文部分内容阅读
对近期出现的开放式Web平台共性特征进行了分析,提出了开放式Web平台由于其系统架构,在可用性、安全性及隐私性等方面存在的问题,并通过实验证明了上述问题的存在.对于增强此类系统可信性,本文认为应重视由RESTfulWebServices远程调用所带来的时间开销,在第三方服务器暂存请求副本并增加DDoS攻击检测功能;开放式Web平台应对其与第三方应用服务器之间的通信进行加密.提出了一种基于任意测试位置的第三方应用评测算法,该算法仅使用较少的测试数据.实验表明,该算法能有效检测存在安全性及隐私性漏洞的第三方应用.
This paper analyzes the common features of the open Web platform that appear recently and puts forward the problems of the open Web platform due to its system architecture, usability, security and privacy, and proves the existence of the above problems through experiments To enhance the credibility of such systems, this paper argues that attention should be paid to the time overhead caused by the remote invocation of RESTfulWebServices, temporary copies of requests in third-party servers and increased detection of DDoS attacks. The open Web platform should respond to its cooperation with third-party application servers This paper proposes a third-party application evaluation algorithm based on arbitrary test location, which uses only a small amount of test data.Experiments show that the algorithm can effectively detect the existence of third-party applications with security and privacy vulnerabilities .