YANG Yang. Research on Security Policy of Web Information System[J]. New Generation of Information Technology, 2023, 6(14): 05-08 DOI: 10.3969/j.issn.2096-6091.2023.14.002.
Research on Security Policy of Web Information System
B/S(Browser/Server)模式下的Web信息系统因对外服务的开放性,以及HTTP(Hypertext Transfer Protocol)等互联网协议存在的缺陷性,容易受到Web攻击,给信息服务提供商和用户带来损失。传统的安全措施往往从某一问题点出发,缺乏整体考虑。本文设计出一种Web应用安全框架,综合网络环境、软硬基础设施、安全策略、管理机制等因素,从多个层面提升安全能力。应用实践证明,该框架能够有效保证完整性、保密性、可用性、可控性和可审查性等安全特性,为Web信息系统安全提供解决方案。
Abstract
Web information systems in B/S (Browser/Server) mode are vulnerable to Web attacks due to the openness of providing external services and the defects of Internet protocols such as HTTP (Hypertext Transfer Protocol)
which brings losses to information service providers and users. Traditional security measures often start from a certain point of view and lack of overall consideration. In this paper
a Web application security framework is designed
which integrates network environment
hard and soft infrastructure
security policy
management mechanism and other factors to improve security capability from multiple levels. Practice shows that the framework could guarantee the security features of integrity
confidentiality
availability
controllability and auditability effectively
and provide a solution for Web information system security.