Architecture of Multi-Dimension Web Application Security Based on OWASP and WASC

WU Zhen,CUI Jian,ZHOU Chang-ling,ZHANG Bei
DOI: https://doi.org/10.3969/j.issn.1001-7445.2011.z1.030
2011-01-01
Abstract:By means of researching and analyzing the reports of multiple security organizations,consortiums and corporations,we discover that web application security is becoming more vital in campus network.Based on the OWASP and the WASC,we designed a multidimension web application security architecture,and used the firewall,web application firewall,intrusion detection system,intrusion prevention system,vulnerability scan system,bastion host and auditing system to implement the architecture.We chose 50 representative web applications from Peking University campus network to study and analyze the logs from these web applications and security devices,and the results prove the validity of the multidimension web application security architecture.
What problem does this paper attempt to address?