欢迎来到天天文库
浏览记录
ID:12480286
大小:37.38 KB
页数:6页
时间:2018-07-17
《外文翻译---web 应用程序的基本安全做法》由会员上传分享,免费在线阅读,更多相关内容在学术论文-天天文库。
1、外文文献翻译英文原文BasicSecurityPracticesforWebApplicationsEvenifyouhavelimitedexperiencewithandknowledgeofapplicationsecurity,therearebasicmeasuresthatyoushouldtaketohelpprotectyourWebapplications.Thefollowingsectionsinthistopicprovideminimum-securityguidelinesthata
2、pplytoallWebapplications.GeneralWebApplicationSecurityRecommendations;RunApplicationswithMinimumPrivileges;KnowYourUsers;GuardAgainstMaliciousUserInput;AccessDatabasesSecurely;CreateSafeErrorMessages;KeepSensitiveInformationSafely;UseCookiesSecurely;GuardAga
3、instDenial-of-ServiceThreats.1.GeneralWebApplicationSecurityRecommendationsEventhemostelaborateapplicationsecuritycanfailifamalicioususercanusesimplewaystogainaccesstoyourcomputers.GeneralWebapplicationsecurityrecommendationsincludethefollowing:Backupdataoft
4、enandkeepyourbackupsphysicallysecure.KeepyourWebserverphysicallysecuresothatunauthorizeduserscannotgainaccesstoit,turnitoff,physicallystealit,andsoon.UsetheWindowsNTFSfilesystem,notFAT32.NTFSofferssubstantiallymoresecuritythanFAT32.ProtecttheWebserverandallo
5、fthecomputersonthesamenetworkwithstrongpasswords.FollowbestpracticesforsecuringInternetInformationServices(IIS).Closeanyunusedportsandturnoffunusedservices.Runaviruscheckerthatmonitorssitetraffic.Useafirewall.LearnaboutandinstallthelatestsecurityupdatesfromM
6、icrosoftandothervendors.UseWindowseventloggingandexaminethelogsfrequentlyforsuspiciousactivity.ThisincludesrepeatedattemptstologontoyoursystemandexcessiverequestsagainstyourWebserver.2.RunApplicationswithMinimumPrivilegesWhenyourapplicationruns,itrunswithina
7、contextthathasspecificprivilegesonthelocalcomputerandpotentiallyonremotecomputers.Forinformationaboutconfiguringapplicationidentity,seeConfiguringASP.NETProcessIdentity.Torunwiththeminimumnumberofprivilegesneeded,followtheseguidelines:Donotrunyourapplication
8、withtheidentityofasystemuser(administrator).Runtheapplicationinthecontextofauserwiththeminimumpracticalprivileges.Setpermissions(ACLs,orAccessControlLists)onalltheresourcesrequiredforyourapplica
此文档下载收益归作者所有