...
首页> 外文期刊>Communications and Network >Web Threats Detection and Prevention Framework
【24h】

Web Threats Detection and Prevention Framework

机译:Web威胁检测和预防框架

获取原文

摘要

The rapid advancement in technology and the increased number of web applications with very short turnaround time caused an increased need for protection from vulnerabilities that grew due to decision makers overlooking the need to be protected from attackers or software developers lacking the skills and experience in writing secure code. Structured Query Language (SQL) Injection, cross-site scripting (XSS), Distributed Denial of service (DDos) and suspicious user behaviour are some of the common types of vulnerabilities in web applications by which the attacker can disclose the web application sensitive information such as credit card numbers and other confidential information. This paper proposes a framework for the detection and prevention of web threats (WTDPF) which is based on preventing the attacker from gaining access to confidential data by studying his behavior during the action of attack and taking preventive measures to reduce the risks of the attack and as well reduce the consequences of such malicious action. The framework consists of phases which begin with the input checking phase, signature based action component phase, alert and response phases. Additionally, the framework has a logging functionality to store and keep track of any action taking place and as well preserving information about the attacker IP address, date and time of the attack, type of the attack, and the mechanism the attacker used. Moreover, we provide experimental results for different kinds of attacks, and we illustrate the success of the proposed framework for dealing with and preventing malicious actions.
机译:技术的飞速发展和Web应用程序数量的增加以及非常短的周转时间导致对漏洞防御的需求日益增加,由于决策者忽视了需要保护免受缺乏安全编写技能和经验的攻击者或软件开发人员的保护,决策者忽略了这些漏洞码。结构化查询语言(SQL)注入,跨站点脚本(XSS),分布式服务拒绝(DDos)和可疑用户行为是Web应用程序中的一些常见漏洞类型,攻击者可以通过这些漏洞来公开Web应用程序敏感信息,例如作为信用卡号和其他机密信息。本文提出了一个用于检测和预防Web威胁的框架(WTDPF),该框架的基础是通过研究攻击者在攻击过程中的行为并采取预防措施来降低攻击风险,从而防止攻击者获得机密数据。并减少此类恶意行为的后果。该框架由以下几个阶段组成:输入检查阶段,基于签名的动作组件阶段,警报和响应阶段。此外,该框架还具有日志记录功能,可以存储和跟踪发生的任何操作,并保留有关攻击者IP地址,攻击日期和时间,攻击类型以及攻击者使用的机制的信息。此外,我们提供了针对各种攻击的实验结果,并说明了所提出的用于处理和预防恶意行为的框架的成功。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号