Implementation of Web Defacement Detection Technique
نویسنده
چکیده
Websites are no longer merely about having an “Internet presence” today, but are also used for commercial transactions and to transfer sensitive data like personal information, credit card number, etc. This rapid proliferation of website has also spawned new threat to business and other organizations. Hackers are developing new techniques to deface website and steal the data from Web server. One kind of such attack on website is Website defacement attack. The term ‘Website defacement’ refers to unauthorized change of the content made either on a single web page (usually default web page) or on entire web site. The content of a defaced web page may be partially changed or it may be fully replaced by another page. Detection of website defacement automatically is very difficult because today web pages are highly dynamic and their degree of dynamism may vary widely across different pages. This paper proposes a hash code based web defacement detection mechanism. The proposed system includes the development of a module for an Apache web server for defacement detection in web pages, and configured it so that defaced web page should not be served by web server to the legitimate user. The proposed system prevents the legitimate user from accessing defaced web pages.
منابع مشابه
A Comparative Study of Anomaly Detection Techniques in Web Site Defacement Detection
Web site defacement, the process of introducing unauthorized modifications to a web site, is a very common form of attack. Detecting such events automatically is very difficult because web pages are highly dynamic and their degree of dynamism, as well as their typical content and appearance, may vary widely across different pages. Anomaly based detection can be a feasible and effective solution...
متن کاملTechniques for Large-Scale Automatic Detection of Web Site Defacements
Web site defacement, the process of introducing unauthorized modifications to a web site, is a very common form of attack. This thesis describes the design and experimental evaluation of a framework that may constitute the basis for a defacement detection service capable of monitoring thousands of remote web sites systematically and automatically. With this framework an organization may join th...
متن کاملMeerkat: Detecting Website Defacements through Image-based Object Recognition
Website defacements and website vandalism can inflict significant harm on the website owner through the loss of sales, the loss in reputation, or because of legal ramifications. Prior work on website defacements detection focused on detecting unauthorized changes to the web server, e.g., via host-based intrusion detection systems or file-based integrity checks. However, most prior approaches la...
متن کاملOff-Path Attacking the Web
We show how an off-path (spoofing-only) attacker can perform cross-site scripting (XSS), cross-site request forgery (CSRF) and site spoofing/defacement attacks, without requiring vulnerabilities in either web-browser or server, and circumventing known defenses. The attacks are practical and require a puppet (malicious script in browser sandbox) running on a victim client machine, and an attacke...
متن کاملDefacement of Colluding Attack Using Blowfish Algorithm
Abstract In web environment, browser extension extends its functionality by retrieving, presenting and traversing the information through web browser. Browser extensions run with ‘high’ privileges which consequences, vulnerable web browser extensions to steal user’s credentials and trap users into leaking sensitive information to unauthorized parties. One of the attack known as Colluding browse...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2015