Towards automated web application logic reconstruction for application level security

نویسندگان

  • George Noseevich
  • Dennis Gamayunov
چکیده

Modern overlay security mechanisms like Web Application Firewalls (WAF) suffer from inability to recognize custom high-level application logic and data objects, which results in low accuracy, high false positives rates, and overhelming manual effort for fine tuning. In this paper we propose an approach to web application modeling for security purposes that could help next-generation WAFs to adapt to specific web applications, and do it automatically whenever possible. We aim at creating multi-layer models that adequately simulate various aspects of web application functionality that are significant for intrusion detection and prevention, including request parsing and routing, reconstruction of actions and data objects, and action interdependencies.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Toward Automated Detection of Logic Vulnerabilities in Web Applications

Web applications are the most common way to make services and data available on the Internet. Unfortunately, with the increase in the number and complexity of these applications, there has also been an increase in the number and complexity of vulnerabilities. Current techniques to identify security problems in web applications have mostly focused on input validation flaws, such as crosssite scr...

متن کامل

MODEL DRIVEN DESIGN OF SECURE HIGH ASSURANCE SYSTEMS: AN INTRODUCTION TO THE OPEN PLATFORM FROM THE USER PERSPECTIVE Steve Boßelmann and Johannes Neubauer and Stefan Naujokat and Bernhard Steffen Chair of Programming Systems

We present DIME, an integrated solution for the rigorous model-driven development of sophisticated web applications based on the Dynamic Web Application (DyWA) Framework, that is designed to flexibly integrate features such as high assurance and security. DIME provides a family of Graphical Domain-Specific Languages (GDSL), each of which tailored towards a specific aspect of typical web applica...

متن کامل

An Integrated Approach to Defence Against Degrading Application-Layer DDoS Attacks

Application layer Distributed Denial of Service (DDoS) attacks are recognized as one of the most damaging attacks on the Internet security today. In our recent work [1], we have shown that unsupervised machine learning can be effectively utilized in the process of distinguishing between regular (human) and automated (web/botnet crawler) visitors to a web site. We have also shown that with a sli...

متن کامل

Exploring the Relationship Between Web Application Development Tools and Security

How should software engineers choose which tools to use to develop secure web applications? Different developers have different opinions regarding which language, framework, or vulnerability-finding tool tends to yield more secure software than another; some believe that there is no difference at all between such tools. This paper adds quantitative data to the discussion and debate. We use manu...

متن کامل

Middleware for semantic-based security and safety management of open services

The trend towards ubiquitous public services is driving the deployment of large-scale, heterogeneous, distributed information services. In order to support automated information access and processing, this information is marked up using semantic metadata models represented using ontology languages such as OWL. The use of such a semantic metadata model is twofold: to enable content-based access ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • CoRR

دوره abs/1511.02564  شماره 

صفحات  -

تاریخ انتشار 2015