- 1、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。。
- 2、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 3、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
- 4、该文档为VIP文档,如果想要下载,成为VIP会员后,下载免费。
- 5、成为VIP后,下载本文档将扣除1次下载权益。下载后,不支持退款、换文档。如有疑问请联系我们。
- 6、成为VIP后,您将拥有八大权益,权益包括:VIP文档下载权益、阅读免打扰、文档格式转换、高级专利检索、专属身份标志、高级客服、多端互通、版权登记。
- 7、VIP文档为合作方或网友上传,每下载1次, 网站将根据用户上传文档的质量评分、类型等,对文档贡献者给予高额补贴、流量扶持。如果你也想贡献VIP文档。上传文档
查看更多
摘要
随着互联网的大规模普及和迅猛发展,各政府机关、企业甚至个人纷纷建立起自己的网站。但由于外部网站需要被公众浏览而暴露在相对开放的环境中,很容易成为了黑客和不法分子的攻击目标。在各种各样的网络安全攻击事件当中,以篡改网站问题最为严重,造成的影响也最为恶劣。本文提出了一种具有主动拒绝非法修改网页文件行为的网站防篡改的改进机制。该机制要求管理员将网页文件加为受控对象,随后在文件驱动层进行检测,当检测到对受控对象有操作行为时,通过对象相关保护方式进行认证,对未通过验证的非法篡改行为予以拒绝。管理员需要修改文件时,通过特定程序输入授权码后进行修改。该机制还能够在保护网站安全的同时保证自身不被非法修改或中断,当被保护系统被非法篡改后,网站管理者将收到短信与邮件报警,从而体现防护的实时性。本系统采用HOOK对本程序线程进行保护,一但选择保护后,本程序将不能在任务管理器中被非法结束。使得入侵者无从下手,达到了主动防御网页篡改行为的目的。
关键词.NET网页防篡改,邮件短信报警,事件触发
ABSTRACT
With the popularity of the Internet and the rapid development of large-scale, government agencies, businesses and even individuals have set up their own websites. However, due to external Web sites need to be exposed to public view and in a relatively open environment, it is easy to become the hackers and criminals target. In a variety of network security attacks were to tamper with the most severe site issues, and most adverse impact. This paper presents a web page with active refusal to modify the file illegal acts to improve the site tamper-resistant mechanism. The mechanism requires the administrator to add the page file to the controlled object, and then detected in the file driver layer, when the detected behavior of the controlled object has operations, the protection mode through the object related to authentication, for failure to verify the illegal tampering by be rejected. Administrators need to modify the file, enter the license key through a specific program after modifications. This mechanism can also protect the site while ensuring its own security is not illegal to modify or discontinue, when the protection system have been illegally tampered with, the site managers will receive SMS and e-mail alert, which reflects the real-time protection. The system uses HOOK protection of the thread, but the choice of a protection, the program will not be illegal in the Task Manager end. Makes the intruder can not start, reaching the proactive behavior of the purpose of tampering with web pages.
KEYWORDS:. NET Web Conte
文档评论(0)