Analysis and research on security risk of Web application
Duan Sheng-qiang · Journal of Xi'an University of Architecture & Technology · 2012
The security problem of Web application and its importance are analyzed in this paper.At the same time,the security property of the Web application is also analyzed and the description of the ten security risks and the responsed precautionary measure and resolution are given including Injection,Cross-Site Scripting(XSS),Broken Authentication and Session Management,Insecure Direct Object References,Cross-Site Request Forgery(CSRF),Security Misconfiguration,Insecure Cryptographic Storage,Failure to Restrict URL Access,Insufficient Transport Layer Protection,Invalidated Redirects and Forwards.For various security problems of Web application,the conventional security technique and its description are recommended.