首页> 外文会议>IFIP TC8 International Conference on Computer Information Systems and Industrial Management >A Proposal of Algorithm for Web Applications Cyber Attack Detection
【24h】

A Proposal of Algorithm for Web Applications Cyber Attack Detection

机译:网络应用网络攻击检测算法提案

获取原文

摘要

Injection attacks (e.g. XSS or SQL) are ranked at the first place in world-wide lists (e.g. MITRE and OWASP). These types of attacks can be easily obfuscated. Therefore it is difficult or even impossible to provide a reliable signature for firewalls that will detect such attacks. In this paper, we have proposed an innovative method for modelling the normal behaviour of web applications. The model is based on information obtained from HTTP requests generated by a client to a web server. We have evaluated our method on CSIC 2010 HTTP Dataset achieving satisfactory results.
机译:注射攻击(例如XSS或SQL)排名在全球列表中的第一名(例如斜切和OWASP)。这些类型的攻击可以很容易地混淆。因此,对于将检测此类攻击的防火墙提供可靠的签名是困难甚至不可能的。在本文中,我们提出了一种创新方法,用于建模Web应用程序的正常行为。该模型基于从客户端生成的HTTP请求到Web服务器获得的信息。我们在实现令人满意的结果的CSIC 2010 HTTP数据集中评估了我们的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号