Web 应用安全开发规范 V1.5
目 录 Table of Contents
1 概述........................................................................................................................................................4
1.1 背景简介.........................................................................................................................................4
1.2 技术框架.........................................................................................................................................5
1.3 使用对象.........................................................................................................................................6
1.4 适用范围.........................................................................................................................................6
1.5 用词约定.........................................................................................................................................6
2 常见WEB安全漏洞..............................................................................................................................7
3 WEB设计安全规范..............................................................................................................................8
3.1 WEB部署要求.................................................................................................................................8
3.2 身份验证.........................................................................................................................................9
3.2.1 口令.......................................................................................................................9
3.2.2 认证.......................................................................................................................9
3.2.3 验证码.................................................................................................................12
3.3 会话管理.......................................................................................................................................12
3.4 权限管理.......................................................................................................................................14
3.5 敏感数据保护...............................................................................................................................15
3.5.1 敏感数据定义.....................................................................................................15
3.5.2 敏感数据存储.....................................................................................................15
3.5.3 敏感数据传输.....................................................................................................17
3.6 安全审计.......................................................................................................................................18
3.7 WEB SERVICE................................................................................................................................19
3.8 RESTFUL WEB SERVICE...............................................................................................................20
3.9 DWR.............................................................................................................................................21
4 WEB编程安全规范............................................................................................................................22
4.1 输入校验.......................................................................................................................................22
4.2 输出编码.......................................................................................................................................26
4.3 上传下载.......................................................................................................................................27
4.4 异常处理.......................................................................................................................................27
2021-8-15
第 2 页, 共 35 页
评论0