摘要
高校网站一直是黑客攻击的重点部位,面对严峻的安全形势,管理部门制定了相应的安全防护方案,采取一定的措施,提高抵御外部攻击的能力。针对我校网站目前存在的问题,提出以下三种方案:使用UrlScan设置一定的规则在IIS之前对URL及请求字符串进行过滤、自主研发服务器管理器对网站文件夹的关键操作进行监控、利用IIS日志对入侵事件追踪,加强对网站的安全防护,减少因攻击而产生的损失。
The university's websites have been the key attack target of hacker. Facing the serious situation, the management work out the corresponding security protection scheme and take some measures to enhance the resistibility of attack. For the existing problem in our websites, this paper proposed three solutions: filtering the URL and query strings by the rules in UrlScan before the IIS、developing the server manager to monitor the folder storing the website、tracing the invasion by the IIS log, which strengthen the website security and reduce the loss due to attack.
出处
《电脑知识与技术(过刊)》
2014年第5X期3254-3256,3271,共4页
Computer Knowledge and Technology
基金
河南省科技计划项目(132300410210)
河南省教育厅科学技术研究重点项目(13A520810
14A520057)
关键词
网站
安全
攻击
防护
IIS日志
监控
过滤
website
security
attack
protection
IIS log
monitor
filter