Synthetic Data Generation and Defense in Depth Measurement of Web Applications

نویسندگان

  • Nathaniel Boggs
  • Hang Zhao
  • Senyao Du
  • Salvatore J. Stolfo
چکیده

Measuring security controls across multiple layers of defense requires realistic data sets and repeatable experiments. However, data sets that are collected from real users often cannot be freely exchanged due to privacy and regulatory concerns. Synthetic datasets, which can be shared, have in the past had critical flaws or at best been one time collections of data focusing on a single layer or type of data. We present a framework for generating synthetic datasets with normal and attack data for web applications across multiple layers simultaneously. The framework is modular and designed for data to be easily recreated in order to vary parameters and allow for inline testing. We build a prototype data generator using the framework to generate nine datasets with data logged on four layers: network, file accesses, system calls, and database simultaneously. We then test nineteen security controls spanning all four layers to determine their sensitivity to dataset changes, compare performance even across layers, compare synthetic data to real production data, and calculate combined defense in depth performance of sets of controls.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

GENERATION OF SYNTHETIC EARTHQUAKE RECORDS BY ARTIFICIAL INTELLIGENCE TECHNIQUES

For seismic resistant design of critical structures, a dynamic analysis, based on either response spectrum or time history is frequently required. Due to the lack of recorded data and randomness of earthquake ground motion that might be experienced by the structure under probable future earthquakes, it is usually difficult to obtain recorded data which fit the necessary parameters (e.g. soil ty...

متن کامل

ایجاد نیمه خودکار مشاپ های سازمانی با استفاده از توصیفات معنایی

Mashups are next generation of web applications. A mashup is a lightweight web application that is created by combining information or capabilities from more than one existing resources to deliver a new and integrated experience to the user. Mashups introduce a new class of integration techniques in enterprises for implementing situational applications (i.e. applications that come together to s...

متن کامل

Sociological Impact of Using Digital (Web-based) Analyses on Performance Measurement and Optimization of Digital Marketing among Young Managers (Case study: Digital-based Companies in Tehran)

This research aims to study the effect of using digital (web-based) analyses in performance measurement and optimization of digital marketing in digital-based companies in Tehran. The data collection tool was a researcher-made questionnaire. A panel of experts and supervisor were asked to measure the validity of the questionnaire. For reliability analysis of this tool, Cronbach’s alpha test was...

متن کامل

Educational Climate Measurement Tools in Medical Sciences Universities: A Review Article

Introduction: Educational climate is one of the most important factors affecting achievement and satisfaction of students and determining their behavior. Measuring educational climate is necessary for reforming and idealizing educational environment. The purpose of this study was to introduce educational climate measurement tools and their subscales and application in medical sciences universit...

متن کامل

تأثیر محیط دیجیتال بر عادت و روش‌های خواندن جوانان

Purpose: In digital age, web applications work as machines that swallow time rapidly. A new generation tendency to use these tools for entertaining and information gathering has changed their habits in type of selected materials and reading practices. In other words, although users currently receive information from internet, they have increasingly become superficial readers who have a little i...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2014