MITM攻击在使用代理服务器的情况中尤其重要。
The MITM attack becomes especially important when talking about proxy servers.
浏览器的同源策略无法阻止CSRF攻击,因为攻击请求被传输到第三方入侵站点的代理中相同的源。
The browser's same-origin policy does not prevent CSRF attacks because the attack requests are transmitted to the same origin in proxy for the intruding third-party site.
这种攻击只在一种情况下可行:入侵者站点使mashup页面为其将请求代理到企业mashup服务器。
This attack is only possible if the intruder site gets the mashup page to proxy the requests to the corporate mashup server for the intruder site.
反向代理服务器可以保护服务器免受病毒攻击和大多数黑客攻击,因为反向代理服务器是惟一能够通过Internet访问的服务器。
A reverse proxy protects the server from virus attacks and most hacking attempts because the reverse proxy server is the only server accessible from the Internet.
此外,该方案不仅满足代理签名的基本性质,还避免了代理权滥用、原始签名人伪造和公钥替换攻击。
Besides having the basic properties of the proxy signature, the new scheme prevents proxy misuse, original signer's forgery and public key substitution attack.
为了抵抗原始签名人的伪造攻击,改进了代理签名密钥的生成过程,并对改进的方案进行了安全性分析。
To eliminate the original signers forgery attacks, a modification of the proxy key generation stage is proposed. Security analysis of the improved scheme is also presented.
在全面分析攻击方案的基础上,构造了一种增强的代理多重签名方案。
Based on the analysis of attack scheme, an improved proxy multi-signature scheme was proposed.
摘要密码的应用可使移动代理免受运行主机上恶意软件的攻击,保持其携带信息的机密性并不受撺扰。
The cryptographic technique provides mobile Agent with a defense against attacks from malicious hosts by maintaining the confidentiality of carryied messages and safeguarding them against tampering.
密码的应用可使移动代理免受运行主机上恶意软件的攻击,保持其携带信息的机密性并不受撺扰。
The cryptographic technique provides mobile Agent with a defense against attacks from malicious hosts by maintaining the confidentiality of carried messages and safeguarding them against tampering.
这里指出s - L - H方案不能抵抗公钥替换攻击,并给出了一个改进的门限代理签名方案。
It is shown here that S-L-H scheme is insecure against the public key substitution attack and an improved threshold proxy signature scheme is proposed.
而且,利用与运行移动代理的主机相关的密钥对运行结果加密,能有效地防止对移动代理运行结果的窥探和篡改攻击。
Still, encrypting the mobile a-gent's result by means of secret key associated with the host on which the agent runs can prevent the result from spying and tampering attack.
具体而言,一个重要方面,必须加以解决的移动商务方案是移动代理免受攻击手法进行恶意主机。
In particular, an important aspect that must be solved for them-commerce scenario is the mobile agent protection from manipulation attacks performed by malicious hosts.
给出了三种攻击并指出于刚等人提出的前向安全的基于身份的代理签密方案是不安全的。
Three attacks on Yu Gang et al's scheme to show that their forward secure proxy-signcryption scheme based on identity is insecure.
该文给出的一种攻击方案表明他们的方案是不安全的,任何代理签名的接收者都可以假冒代理人对任意的消息生成有效的签名。
However, their scheme is insecure by presenting a forgery attack, any receiver can impersonate the proxy signer to sign any message without holding the responsibility.
本发明包括用于利用代理服务器来防止用户设备受到网络攻击的方法和装置。
The invention includes a method and an apparatus for protecting a user device from web attacks using a proxy server.
安全分析结果表明,与L - L - C - Z门限代理签密协议相比,该改进门限代理签密协议能够承受接收方公钥替换攻击。
Security analysis results show that compared with L-L-C-Z threshold proxy signcryption protocol, the improved threshold proxy signcryption protocol can withstand the public key substitution attack.
方案不仅能抵抗伪造攻击和满足代理签名的性质,而且具有前向安全。
The scheme not only can effectively resist the forgery attacks and satisfy all security properties of proxy signature, but also has the properties of forward security.
同时,也指出了另外一个缺陷即攻击者可以假冒原始签名人将任何消息的代理签名权委托给任何代理人。
It is pointed out that they have the same defect in security which is the attacker can forge an effective signer to actualize an attack of public key replace.
同时,利用检测代理反馈回来的信息,控制台可以检测出单个代理所无法检测的分布式攻击。
At the same time, the console may detect distribute attack which single agent is unable to detect.
采用一种新型基于角色的强制访问控制,防攻击和防病毒功能的代理机制。
The firewall is to adopt a new role-based mandatory access control, anti-attack and anti-virus proxy mechanism.
YBX代理多重签名方案是不安全的,攻击者在不知道原始签名者密钥的情况下,能够伪造代理签名密钥,假冒代理签名者对文件进行签名。
The proxy multi-signature scheme called YBX is not safe. An attacker can forge the key pair of proxy signature without the original private key, and disguise himself as proxy to sign document.
对一种基于双线性对的新型门限代理签名方案进行了密码分析,发现该门限代理签名方案不能抵抗伪造攻击和公钥替换攻击。
Through the cryptanalysis of a threshold proxy signature scheme in literature, the scheme could not resist insider attacks and public-key substitute attacks.
对无证书代理签名方案进行安全性分析,指出该方案对于公钥替换攻击是不安全的,并给出具体的攻击方法。
This paper analyzes the security of a certificateless proxy signature scheme and shows that it is insecure against the public key replacement attack in certificateless cryptosystems.
即使当前时段的代理签名密钥泄露,攻击者也无法得到以前时段的代理签名。
Even if the current secret key of proxy signer has been leaked, the attacker can't forge the proxy signature of the past period time.
该协议灵活运用HMAC,确保代理每次租借时客户总是“激活的”,从而尽量避免恶意攻击。
The protocol USES HMAC to guarantee the client being active, then protects leasing from attacks. 5 in the aspect of UOWHF discovery, tree-Shoup construction is put forward in this paper.
该协议灵活运用HMAC,确保代理每次租借时客户总是“激活的”,从而尽量避免恶意攻击。
The protocol USES HMAC to guarantee the client being active, then protects leasing from attacks. 5 in the aspect of UOWHF discovery, tree-Shoup construction is put forward in this paper.
应用推荐