Computer and Modernization

Previous Articles     Next Articles

Multi-dimensional Monitoring System for Website Security Based on Cloud Platform

  

  1. 1. Beijing Guo Dian Tong Network Technology Co., Ltd., Beijing 100070, China;2. School of Electronic Information and Electrical Engineering, Shanghai Jiaotong University, Shanghai 200240, China;3. Information and Telecommunication Branch of State Grid Zhejiang Electric Power Company, Hangzhou 310007, China;4. State Grid Jibei Electric Power Company, Beijing 100053, China
  • Received:2015-10-16 Online:2016-01-22 Published:2016-01-26

Abstract:  A multi-dimensional monitoring system for website security based on cloud platform utilizes cloud computing technology and monitors website security from three dimensions including availability, security events and Web vulnerabilities. Correlation analysis of the monitoring data is conducted meanwhile. The system concurrently and periodically monitors the large-scale websites comprehensively utilizing several key technologies including rapid detection technology based on static source code analysis towards website hang cockhorse, hidden chain detection technology based on native Bayes, SQL injection attack blind detection technology based on page similarity and XSS detection technology based on high precision DOM locator. The system improves the accuracy, rates of missing report and false alarm in the detection of website defacement which provides timely and accurate basis for the website security administration and maintenance.

Key words: cloud computing, multi-dimensional monitoring, website security, vulnerability scanning, security incident

CLC Number: