首页> 外文会议>IFIP TC 8 international conference on computer information systems and industrial management >A Proposal of Algorithm for Web Applications Cyber Attack Detection
【24h】

A Proposal of Algorithm for Web Applications Cyber Attack Detection

机译:Web应用网络攻击检测算法的建议

获取原文

摘要

Injection attacks (e.g. XSS or SQL) are ranked at the first place in world-wide lists (e.g. MITRE and OWASP). These types of attacks can be easily obfuscated. Therefore it is difficult or even impossible to provide a reliable signature for firewalls that will detect such attacks. In this paper, we have proposed an innovative method for modelling the normal behaviour of web applications. The model is based on information obtained from HTTP requests generated by a client to a web server. We have evaluated our method on CSIC 2010 HTTP Dataset achieving satisfactory results.
机译:注入攻击(例如XSS或SQL)在全球列表(例如MITER和OWASP)中排名第一。这些类型的攻击很容易混淆。因此,很难甚至不可能为将检测到此类攻击的防火墙提供可靠的签名。在本文中,我们提出了一种创新的方法来对Web应用程序的正常行为进行建模。该模型基于从客户端向Web服务器生成的HTTP请求中获取的信息。我们在CSIC 2010 HTTP数据集上评估了我们的方法,取得了令人满意的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号