GB/T 35281-2017 in English
VALIDInformation security technology—Security technique requirements for application servers in mobile internet
- Issued on:2017-12-29
- Implemented on:2018-07-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
Price(USD):
$220.00
$214.00
$214.00
《GB/T 35281-2017信息安全技术 移动互联网应用服务器安全技术要求》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Interpretation of the National Standard of the People's Republic of China GB/T 35281—2017
Core Framework of Security Technical Requirements for Mobile Internet Application Servers
| Dimensions | Key Requirements | Implementation Focus |
|---|---|---|
| Data Security | User Data Integrity, Confidentiality and Anonymization | Encrypted Storage, Regular Backup, Principle of Least Privileges |
| Business Security | Security Specifications for Payment, Push, Advertising and Instant Messaging | Prevent SQL Injection and XSS Attacks, and Ensure Encrypted Transmission of Payment Information |
| System Security | Security configuration of operating system, middleware and database | Update patches in time, close non-essential ports, and strengthen access control |
Implementation suggestions and best practices
1. Three-layer protection strategy for data security:
- At the storage level: Use encryption algorithms to protect sensitive data, such as AES-256.
- At the transmission level: Ensure the security of data in the network through the HTTPS protocol.
- At the processing level: Adopt the principle of minimization and only process necessary user information.
2. Multi-dimensional guarantee of business security:
- Payment business: Follow the JR/T0095-2012 standard to ensure that payment information is not leaked or abused.
- Ad push: Review the security of third-party links to avoid malicious website targeting.
- Instant messaging: Real-time security scanning of files and messages to prevent the spread of malicious code.
3. Layered protection of system security:
- Operating system level: Disable non-essential accounts and services, and strengthen access control policies.
- Middleware level: Regularly update software versions, close default components and ports.
- Database level: Limit database access rights to prevent unauthorized queries.
Sample only — not a preview of GB/T 35281-2017

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.