计算机与现代化 ›› 2012, Vol. 208 ›› Issue (12): 119-122,.doi: 10.3969/j.issn.1006-2475.2012.12.031

• 信息安全 • 上一篇    下一篇

基于Ajax的Web攻击及防御方法

王竞超,刘光耀   

  1. 华北计算技术研究所航空信息系统部,北京100083
  • 收稿日期:2012-11-02 修回日期:1900-01-01 出版日期:2012-12-22 发布日期:2012-12-22

Web Attacks and Defense Methods Based on Ajax

WANG Jing-chao, LIU Guang-yao   

  1. Department of Aviation Information System, North China Institute of Computing Technology, Beijing 100083, China
  • Received:2012-11-02 Revised:1900-01-01 Online:2012-12-22 Published:2012-12-22

摘要: Ajax作为Web 2.0的核心技术,可以异步地向服务器发出请求并实现页面的局部刷新,已经成为开发Web应用的必备技术之一。伴随着此项技术的蓬勃发展,越来越多的安全问题也浮出水面。本文分析基于Ajax的几种Web攻击方式和防御方法,并对其中一种攻击进行实例分析,验证文中提出的防御方法的有效性。

关键词: Ajax, Web攻击, 防御方法

Abstract: Ajax as a core technology of Web 2.0, can send request to server asynchronously and make partial page refresh, which has been an essential technology for developing Web applications. Along with this technology booming, more and more security issues also emerge. This paper analyzes several Ajax Web-based attack and defense methods, and carries out case analyses based on one of the attacks, to verify the effectiveness of the proposed defense methods.

Key words: Ajax, Web attack, defense method

中图分类号: