【24h】

Anomaly detection of web-based attacks

机译:基于Web的攻击的异常检测

获取原文

摘要

Web-based vulnerabilities represent a substantial portion of the security exposures of computer networks. In order to detect known web-based attacks, misuse detection systems are equipped with a large number of signatures. Unfortunately, it is difficult to keep up with the daily disclosure of web-related vulnerabilities, and, in addition, vulnerabilities may be introduced by installation-specific web-based applications. Therefore, misuse detection systems should be complemented with anomaly detection systems. This paper presents an intrusion detection system that uses a number of different anomaly detection techniques to detect attacks against web servers and web-based applications. The system correlates the server-side programs referenced by client queries with the parameters contained in these queries. The application-specific characteristics of the parameters allow the system to perform focused analysis and produce a reduced number of false positives. The system derives automatically the parameter profiles associated with web applications (e.g., length and structure of parameters) from the analyzed data. Therefore, it can be deployed in very different application environments without having to perform time-consuming tuning and configuration.
机译:基于Web的漏洞占计算机网络安全隐患的很大一部分。为了检测已知的基于Web的攻击,滥用检测系统配有大量签名。不幸的是,很难跟上与Web相关的漏洞的每日披露,此外,特定于安装的基于Web的应用程序可能会引入这些漏洞。因此,滥用检测系统应补充异常检测系统。本文介绍了一种入侵检测系统,该系统使用多种不同的异常检测技术来检测针对Web服务器和基于Web的应用程序的攻击。系统将客户端查询所引用的服务器端程序与这些查询中包含的参数相关联。参数的特定于应用程序的特征允许系统执行重点分析并减少误报次数。系统从分析的数据中自动导出与Web应用程序关联的参数配置文件(例如,参数的长度和结构)。因此,它可以部署在非常不同的应用程序环境中,而不必执行耗时的调整和配置。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号