Web security enhancement scheme based on Web application firewall
Zhengde Zhai · Computer Engineering and Applications Journal · 2011
Traditional Web Application Firewalls(WAF) detect attacks are based on inner attack fingerprints and can not detect those kinds of status stealing and tamper.Active security based on WAF is proposed,which enables WAFs to participate in and enhance the security of the HTTP sessions between clients and servers.Security enhancement schemes to defend against HTTP session hijacking,hidden button value manipulation,cookie manipulation are explained.Those schemes can be used to enhance WAF defense ability and improve Web application security.