Font Size: a A A

Design And Implementation Of Cross-platform Website Anti-tamper System Based On File Filter Driver

Posted on:2014-06-27Degree:MasterType:Thesis
Country:ChinaCandidate:Y X LinFull Text:PDF
GTID:2268330425975916Subject:Software engineering
Abstract/Summary:
Nowadays, as the Internet security problem is getting serious, theintellectualization and simplification of hacking implements results to an increase ofthe frequency and spectrum of websites being attacked. According to the reportconducted by the CNCERT/C, tampering has become prevailing among Internetsecurity accidents. As the Internet develops and thrives, the websites of thegovernments, companies and some other relevant organizations play a much moreimportant role than before, it is highly stressed that we should ensure the security andauthenticity of information as well as the benefit of relevant organizations. Therefore,the importance of the Internet security maintenance has been emphasized.Considering this, tamper-proof technology emerges and comes to mature gradually.Since the defense function of existing tamper-proof system is not perfect, onewebsite tamper-proof system combined with security centralized management,four-layer protection, active defense as well as passive defense is discussed in thispaper. The centralized management refers to a management platform, which canprovide convenient surveillance and operation for users through deploying agent ofdifferent Web servers with B/S structure. Four-layer protection integrates file systemfilter driver module, event trigger, core embedded module with anti-SQL-injection tohelp defend the website with a linkage awaken strategy from Hackers. Theactive/passive defense is to safeguard the website by means of different features ofprotection technologies. The file system filter driver module offers active defense,which refuses hacking tampering in millisecond. Passive defense function recoversthe tampering through trigger module and core embedded module.The test result shows that the system achieves the expected goal, which meansthat it can active defend the tampering through driver filtering. Other modules canrecover the tampered files after active defend is skipped. Thus, no tampered web pagewill be exposed to the users. With the website tamper-proof system, the websiteaverage response only delays for0.202s and the access speed is reduced at only4.77%.
Keywords/Search Tags:File system, Filter driver, Website tamper-proof, Active defence, Coreembedded technology
Related items