首页> 外文会议>Federated Conference on Computer Science and Information Systems >A new WAF-based architecture for protecting web applications against CSRF attacks in malicious environment
【24h】

A new WAF-based architecture for protecting web applications against CSRF attacks in malicious environment

机译:一种新的基于WAF的架构,用于保护Web应用程序对恶意环境中的CSRF攻击

获取原文

摘要

Web application firewall is an application firewall for HTTP applications. Typical WAF uses static analysis of HTTP request, defined as a set of rules, to find potentially dangerous payloads in the requests. Generally, these rules cover common attacks such as cross-site scripting (XSS) and SQL injection which are server-related attacks. Cross-site scripting is client-side attack however the server is attacked and forced to return malicious response. Rule-based approach becomes useless when the attack is client-related, for example employing malware on the banking site. Malware allows to change the transfer data. This scenario is hard to detect because the browser displays valid transfer data and data is changed to the thieves' accounts number at the communication stage. In this paper we introduce a new web-based architecture for protecting web applications against CSRF attacks in malicious environemnt. In our approach we extend a classic, static WAF approach with historical and behavioral analysis, based on actions performed by the user in the past.
机译:Web应用程序防火墙是HTTP应用程序的应用程序防火墙。典型的WAF使用HTTP请求的静态分析,定义为一组规则,以在请求中找到潜在的危险有效载荷。通常,这些规则涵盖了常见的攻击,例如跨站点脚本(XS)和SQL注入,它与服务器相关的攻击。跨站点脚本是客户端攻击,但服务器受到攻击并强制返回恶意响应。当攻击与客户相关的攻击有关时,基于规则的方法变得无用,例如在银行网站上使用恶意软件。恶意软件允许更改传输数据。这种情况难以检测,因为浏览器显示有效的传输数据,数据被更改为通信阶段的盗头的帐号。在本文中,我们介绍了一种新的基于Web的架构,用于保护Web应用程序免受恶意环境中的CSRF攻击。在我们的方法中,我们基于用户过去所执行的行动,扩展了历史和行为分析的经典静态WAF方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号