论文部分内容阅读
随着公安交通管理信息化建设和应用的深入,信息系统应用安全研究与应用越来越受到重视,鉴于此,该文以公安交通管理信息系统为研究对象,从身份认证、访问控制、数据安全多个方面对Web应用安全防御技术进行研究,确立相应的防御方法和技术手段。并通过Spring技术架构中面向切面编程技术,将应用安全防御方法和技术的程序代码从具体的业务逻辑中分离出来,建立基于AOP的安全程序包负责Web应用的安全,嵌入信息系统软件中,而业务逻辑程序不必关心应用的安全性,从而建立可扩展、低耦合的安全信息系统。
With the deepening of informatization construction and application of public security traffic management, more and more attention has been paid to the research and application of information system application security. In view of this, this paper takes public security traffic management information system as the research object, from the aspects of identity authentication, access control, data security Many aspects of Web application security defense technology to study, establish the appropriate defense methods and technical means. And through the Spring technology architecture oriented aspect programming technology, application security defense methods and techniques of the program code from the specific business logic separated from the establishment of AOP-based security package is responsible for the safety of Web applications embedded in the information system software, and Business logic programs do not have to worry about the security of the application, so as to create a scalable, low-coupling security information system.