首页> 外国专利> DETECTING ATTACKS ON WEB APPLICATIONS USING SERVER LOGS

DETECTING ATTACKS ON WEB APPLICATIONS USING SERVER LOGS

机译:使用服务器日志检测Web应用程序上的攻击

摘要

A previously-unknown type of attack on a web application can be detected dynamically using server logs. An alert can be raised for an application that returns a valid response to the potential attacker (e.g., when an http (hypertext transfer protocol) status code of 200 is returned to the requestor). Server logs can be analyzed to identify an external computer that uses the same attack methodology on multiple targets. The external computer may attempt to access the same Uniform Resource Identifier (URI) on various web sites. In many cases, the http status code that is returned is an error code. Characteristics such as but not limited to fast crawling and numerous error status codes being returned to a particular requestor can be used by a machine learning (ML) system to identify potentially malicious external computing devices and/or vulnerable URIs.
机译:可以使用服务器日志动态检测Web应用程序上以前未知的攻击类型。可以针对向潜在攻击者返回有效响应的应用程序发出警报(例如,当HTTP(超文本传输​​协议)状态码200返回给请求者时)。可以分析服务器日志,以识别对多个目标使用相同攻击方法的外部计算机。外部计算机可能会尝试访问各种网站上的同一统一资源标识符(URI)。在许多情况下,返回的http状态代码是错误代码。机器学习(ML)系统可以使用诸如但不限于快速爬网和返回给特定请求者的众多错误状态代码之类的特征来识别潜在的恶意外部计算设备和/或易受攻击的URI。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号