【24h】

Web Application Security through Gene Expression Programming

机译:通过基因表达编程的Web应用程序安全

获取原文

摘要

In the paper we present a novel approach based on applying a modern metaheuristic Gene Expression Programming (GEP) to detecting web application attacks. This class of attacks relates to malicious activity of an intruder against applications, which use a database for storing data. The application uses SQL to retrieve data from the database and web server mechanisms to put them in a web browser. A poor implementation allows an attacker to modify SQL statements originally developed by a programmer, which leads to stealing or modifying data to which the attacker has not privileges. Intrusion detection problem is transformed into classification problem, which the objective is to classify SQL queries between either normal or malicious queries. GEP is used to find a function used for classification of SQL queries. Experimental results are presented on the basis of SQL queries of different length. The findings show that the efficiency of detecting SQL statements representing attacks depends on the length of SQL statements.
机译:在本文中,我们提出了一种基于应用现代元启发式基因表达编程(GEP)来检测Web应用程序攻击的新颖方法。此类攻击与入侵者针对使用数据库存储数据的应用程序的恶意活动有关。该应用程序使用SQL从数据库中检索数据,并使用Web服务器机制将其放入Web浏览器中。较差的实现方式使攻击者可以修改最初由程序员开发的SQL语句,从而导致窃取或修改攻击者没有特权的数据。入侵检测问题被转化为分类问题,其目的是在正常查询或恶意查询之间对SQL查询进行分类。 GEP用于查找用于SQL查询分类的函数。实验结果是基于不同长度的SQL查询给出的。研究结果表明,检测表示攻击的SQL语句的效率取决于SQL语句的长度。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号