Security Enhancement for Web Applications in Education Platform at Chinese Academy of Sciences

Luo Qihan,Chen Shenlong,Xing Luyi,Li Ning,Zhang Yuanchao,Liu Peng,Wang Jian,Wen Guanxing,Zhang Yuqing,Liu Zhenqing,Liu Yuzhu
2011-01-01
Abstract:Education platform at Chinese Academy of Sciences is aiming at providing information support for cultivating high-level scientific specialists. Its web applications are large-scale, high-coupling and strong-interactive. As a result, it confronts many potential security risks. In this paper, we developed a target-oriented security enhancement methodology, which is implemented effectively in the web applications. With it, we have discovered and fixed 128 web security vulnerabilities. After the secure programming training, the sum of the two principal vulnerabilities, i.e. SQL injection and XSS, has dropped by 55.10%. Thus the web applications are secured remarkably.
What problem does this paper attempt to address?