作者: Shuo Wen , Yuan Xue , Jing Xu , Hongji Yang , Xiaohong Li
关键词: World Wide Web 、 Web application 、 Web page 、 Web application security 、 Web modeling 、 Data access 、 NoSQL 、 Data modeling 、 Session (web analytics) 、 Access control 、 Database 、 Computer science
摘要: Access control is an extremely important and error-prone practice during web application. The emergence of NoSQL databases the flexible data models they bring impose new challenges on implementation access within applications. This paper presents Scout, a novel methodology for discovering vulnerabilities in existing Meanwhile (1) features database can be addressed (2) neither application source code nor server-side session information from developers required. implements prototype which targets MongoDB backend By automatically protocol layer stack, Scout introduces operation model precisely representing actions performed application, as well inferring policies. shown to able identify comprehensive applications, generate detailed report facilitator manually fix identified vulnerabilities.