计算机应用 ›› 2010, Vol. 30 ›› Issue (8): 2134-2138.

• 信息安全 • 上一篇    下一篇

Web服务恶意内容攻击检测技术

黄康宇1,吴礼发2,吴海佳2   

  1. 1. 解放军理工大学
    2.
  • 收稿日期:2010-02-25 修回日期:2010-03-09 发布日期:2010-07-30 出版日期:2010-08-01
  • 通讯作者: 黄康宇
  • 基金资助:
    国防预研基金

Detection of malicious content attacks on Web services

  • Received:2010-02-25 Revised:2010-03-09 Online:2010-07-30 Published:2010-08-01
  • Contact: HUNAG KangYu

摘要: 基于SOAP消息的恶意内容攻击对Web服务的应用与推广具有很大的影响,但目前尚缺乏能有效检测SOAP消息中恶意内容的方法,为此提出了一种新的SOAP消息特征检测方法。通过定义SOAP项和SOAP规则来描述恶意内容的特征,提出了SOAP消息解析算法和SOAP规则匹配算法,用来实施恶意内容的特征检测。根据提出的方法,设计并实现了一个Web服务攻击检测的原型系统。攻击检测实验和性能分析实验的结果表明,该方法有较好的检测效果和性能。

关键词: Web服务, 攻击, SOAP消息, 恶意内容, 特征检测

Abstract: Malicious content attacks based on SOAP messages have great impact on application and popularization of Web services. In order to detect the malicious content in SOAP message, this paper proposed a new method of SOAP message signature detection. This method defined the SOAP Item and SOAP Rule to describe the feature of malicious content, and introduced the SOAP message parsing algorithm and SOAP rule matching algorithm to detect the malicious content attacks detection. According to this proposed method, a prototype system of Web services attack detection was designed and implemented. The experimental results of attack detection and performance analysis show that this system has good detection effect and performance.

Key words: Web service, attack, SOAP message, malicious content, signature detection