Intrusion Detection System based on Ontology for Web Applications
نویسنده
چکیده
Web application security is the major security concern for e-business and information sharing community. The use of e-business and information sharing community are exponentially increased and due to this cyber threats also increased. Current research shows that more than 75% attacks are being deployed at application layer and that of 90% applications are vulnerable to these attacks. Nowadays it is very important to maintain a high level security to ensure safe and trusted communication of information between various organizations. So Intrusion Detection Systems have become a needful component in terms of computer and network security. Intrusion Detection Systems (IDSs) are one of the most useful tools to identifying malicious attempts over the network and protecting the systems without modifying the end-user software. In our propose system we are using novel approach for effective defense against the application level attacks. We discuss about utilizing methods and techniques of semantic web in the Intrusion Detection Systems based on ontology. Which specify the different categories of attacks? The system semantically analyzes the specific field of payload and headers where attack is possible. Inference ability of the system provides the capability for detecting the zero day and complex web application attacks that easily eludes packet level inspection. The propose system is time efficient by analyzing the specified field of protocol, and able to provide significant search space reduction as well as low false positive rate and high detection rate. To implement and measure the performance of our system we used the KDD99 benchmark dataset and obtained reasonable detection rate. Protégé is an open source tool used to develop our System.
منابع مشابه
A Lightweight Intrusion Detection System Based on Specifications to Improve Security in Wireless Sensor Networks
Due to the prevalence of Wireless Sensor Networks (WSNs) in the many mission-critical applications such as military areas, security has been considered as one of the essential parameters in Quality of Service (QoS), and Intrusion Detection System (IDS) is considered as a fundamental requirement for security in these networks. This paper presents a lightweight Intrusion Detection System to prote...
متن کاملSecuring Cluster-heads in Wireless Sensor Networks by a Hybrid Intrusion Detection System Based on Data Mining
Cluster-based Wireless Sensor Network (CWSN) is a kind of WSNs that because of avoiding long distance communications, preserve the energy of nodes and so is attractive for related applications. The criticality of most applications of WSNs and also their unattended nature, makes sensor nodes often susceptible to many types of attacks. Based on this fact, it is clear that cluster heads (CHs) are ...
متن کاملAn Ontology-supported Outbound Intrusion Detection System
Outbound intrusion detection is a systems vigilance approach that aims at limiting the effects of a security threat by collectively scrutinizing outgoing traffic and local system activity. This paper summarizes the design and implementation of FROID, an outbound intrusion detection prototype built with agent technology that exploits the semantic power of ontologies in order to enable collaborat...
متن کاملA hybrid approach for database intrusion detection at transaction and inter-transaction levels
Nowadays, information plays an important role in organizations. Sensitive information is often stored in databases. Traditional mechanisms such as encryption, access control, and authentication cannot provide a high level of confidence. Therefore, the existence of Intrusion Detection Systems in databases is necessary. In this paper, we propose an intrusion detection system for detecting attacks...
متن کاملAnomaly-based Web Attack Detection: The Application of Deep Neural Network Seq2Seq With Attention Mechanism
Today, the use of the Internet and Internet sites has been an integrated part of the people’s lives, and most activities and important data are in the Internet websites. Thus, attempts to intrude into these websites have grown exponentially. Intrusion detection systems (IDS) of web attacks are an approach to protect users. But, these systems are suffering from such drawbacks as low accuracy in ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2013