首页> 外文会议>Computer Security Applications Conference >A Stateful Intrusion Detection System for World-Wide Web Servers
【24h】

A Stateful Intrusion Detection System for World-Wide Web Servers

机译:全球网络服务器的有状态入侵检测系统

获取原文

摘要

Web servers are ubiquitous, remotely accessible, and often misconfigured. In addition, custom web-based applications may introduce vulnerabilities that are overlooked even by the most security-conscious server administrators. Consequently, web servers are a popular target for hackers. To mitigate the security exposure associated with web servers, intrusion detection systems are deployed to analyze and screen incoming requests. The goal is to perform early detection of malicious activity and possibly prevent more serious damage to the protected site. Even though intrusion detection is critical for the security of web servers, the intrusion detection systems available today only perform very simple analyses and are often vulnerable to simple evasion techniques. In addition, most systems do not provide sophisticated attack languages that allow a system administrator to specify custom, complex attack scenarios to be detected. This paper presents WebSTAT, an intrusion detection system that analyzes web requests looking for evidence of malicious behavior. The system is novel in several ways. First of all, it provides a sophisticated language to describe multistep attacks in terms of states and transitions. In addition, the modular nature of the system supports the integrated analysis of network traffic sent to the server host, operating system-level audit data produced by the server host, and the access logs produced by the web server. By correlating different streams of events, it is possible to achieve more effective detection of web-based attacks.
机译:Web服务器是普遍存在的,远程访问,并且通常错误配置。此外,基于自定义Web的应用程序可能会引入甚至由最安全的服务器管理员忽略忽略的漏洞。因此,Web服务器是黑客的流行目标。为了减轻与Web服务器相关联的安全曝光,部署入侵检测系统以分析和筛选传入请求。目标是早期检测恶意活动,并可能防止受保护场所的严重损害。尽管入侵检测对于Web服务器的安全性至关重要,但今天可用的入侵检测系统仅执行非常简单的分析,并且通常容易受到简单的逃避技术。此外,大多数系统不提供复杂的攻击语言,允许系统管理员指定要检测的自定义,复杂的攻击方案。本文介绍了WebStat,一种入侵检测系统,分析了Web请求寻找恶意行为的证据。该系统以多种方式是新颖的。首先,它提供了一种复杂的语言,可以在各州和转换方面描述多学期攻击。此外,系统的模块化性质支持向服务器主机发送到服务器主机的网络流量的集成分析,操作系统主机生成的系统级审计数据以及Web服务器生成的访问日志。通过与不同的事件流相关,可以实现更有效的基于Web的攻击检测。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号