Artificial Intelligent Web Application Firewall for advanced detection of web injection attacks

被引:0
|
作者
Roman-Gallego, Jesus-Angel [1 ]
Perez-Delgado, Maria-Luisa [1 ]
Vinuela, Marcos Luengo [1 ]
Vega-Hernandez, Maria-Concepcion [1 ]
机构
[1] Univ Salamanca, Escuela Politecn Super Zamora, Ave Requejo 33, Zamora 49022, Spain
关键词
artificial intelligence; injection; machine learning; vulnerability; web application firewall; LINEAR-REGRESSION; CLASSIFICATION; MODEL;
D O I
10.1111/exsy.13505
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Currently, web services-based applications have an important presence in public and private organizations. The vulnerabilities that these types of applications may have pose an inherent potential risk to the business model of these organizations. These applications have the inherent risk of being used by organizations in such a way that their activity is affected and they become the main entry point for attackers who want to breach their security. The main barrier to this type of attack are web application firewalls (WAF), which are responsible for processing Hypertext Transfer Protocol requests between clients and web servers, classifying them and rejecting malicious requests. This type of (WAF) applications, for the most part, have regular expressions that correspond to general rules and allow detecting malicious requests that follow a pattern contained in them. However, due to the knowledge of these rules by attackers, it is easy to circumvent security and to impersonate a malicious request by an innocuous request. Therefore, in this article, we present a study of different models based on artificial intelligence techniques as Naive Bayes, k-nearest neighbors, support vector machines, and linear regression to test their effectiveness in detecting malicious requests from a synthetic dataset containing more than 100,000 requests. The results obtained show that the implementation of these methods optimize the detection of malicious requests obtaining results between 92% and 99% of success in their classification.
引用
收藏
页数:18
相关论文
共 50 条
  • [1] Deep Learning Technique-Enabled Web Application Firewall for the Detection of Web Attacks
    Dawadi, Babu R.
    Adhikari, Bibek
    Srivastava, Devesh K.
    SENSORS, 2023, 23 (04)
  • [2] Artificial neural network based web application firewall for SQL injection
    Moosa, Asaad
    World Academy of Science, Engineering and Technology, 2010, 64 : 12 - 21
  • [3] Artificial neural network based web application firewall for SQL injection
    Moosa, Asaad
    World Academy of Science, Engineering and Technology, 2010, 40 : 12 - 21
  • [4] Development of a Hybrid Web Application Firewall to Prevent Web Based Attacks
    Tekerek, Adem
    Gemci, Cemal
    Bay, Omer Faruk
    2014 IEEE 8TH INTERNATIONAL CONFERENCE ON APPLICATION OF INFORMATION AND COMMUNICATION TECHNOLOGIES (AICT), 2014, : 51 - 54
  • [5] Web-to-Application Injection Attacks on Android: Characterization and Detection
    Hassanshahi, Behnaz
    Jia, Yaoqi
    Yap, Roland H. C.
    Saxena, Prateek
    Liang, Zhenkai
    COMPUTER SECURITY - ESORICS 2015, PT II, 2015, 9327 : 577 - 598
  • [6] Toward an SDN-Based Web Application Firewall: Defending against SQL Injection Attacks
    Alotaibi, Fahad M.
    Vassilakis, Vassilios G.
    FUTURE INTERNET, 2023, 15 (05)
  • [7] Development of Web Application Firewall Based on Artificial Intelligence
    Roman-Gallego, Jesus-Angel
    Perez-Delgado, Maria-Luisa
    Vinuela, Marcos Luengo
    NEW TRENDS IN DISRUPTIVE TECHNOLOGIES, TECH ETHICS AND ARTIFICIAL INTELLIGENCE, DITTET 2023, 2023, 1452 : 18 - 27
  • [8] Improving Web Application Firewalls to Detect Advanced SQL Injection Attacks
    Makiou, Abdelhamid
    Begriche, Youcef
    Serhrouchni, Ahmed
    2014 10TH INTERNATIONAL CONFERENCE ON INFORMATION ASSURANCE AND SECURITY (IAS), 2014, : 35 - 40
  • [9] A Metamodel for Web Application Injection Attacks and Countermeasures
    Holm, Hannes
    Ekstedt, Mathias
    TRENDS IN ENTERPRISE ARCHITECTURE RESEARCH AND PRACTICE-DRIVEN RESEARCH ON ENTERPRISE TRANSFORMATION, 2012, 131 : 198 - 217
  • [10] An Adaptive Web Application Firewall
    Calvo, Miguel
    Beltran, Marta
    SECRYPT : PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2022, : 96 - 107