Web Application Critical Resources Protection
Bogdan Korniyenko, Lesya Ladieva, Liliya Galata, Olesya Yakovenko, Andrii Nesteruk, Viktoriia Ivannikova · 2021
Developed web application protection system by using modern technologies NET Framework, ASP. NET Core, EF, SSMS, Swagger. The system is resistant to changes and outside interference, able to prevent unauthorized access. The main types of vulnerabilities in web applications are considered. The most popular ready-made services for the implementation of the appropriate protection are described. The white list model of developing secure web applications and the main steps of the model implementation is defined. Implemented a white list model for a web application by using a system of roles and access. The server part of the web application has been developed, which includes the built-in functionality of the basic methods of hacking prevention. Impact of SQL injection through project architecture is not possible. A method for accessing private user information has been developed by using the Rijndael encryption algorithm.