Artificial Intelligent Web Application Firewall for advanced detection of web injection attacks

被引:0
|
作者
Roman-Gallego, Jesus-Angel [1 ]
Perez-Delgado, Maria-Luisa [1 ]
Vinuela, Marcos Luengo [1 ]
Vega-Hernandez, Maria-Concepcion [1 ]
机构
[1] Univ Salamanca, Escuela Politecn Super Zamora, Ave Requejo 33, Zamora 49022, Spain
关键词
artificial intelligence; injection; machine learning; vulnerability; web application firewall; LINEAR-REGRESSION; CLASSIFICATION; MODEL;
D O I
10.1111/exsy.13505
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Currently, web services-based applications have an important presence in public and private organizations. The vulnerabilities that these types of applications may have pose an inherent potential risk to the business model of these organizations. These applications have the inherent risk of being used by organizations in such a way that their activity is affected and they become the main entry point for attackers who want to breach their security. The main barrier to this type of attack are web application firewalls (WAF), which are responsible for processing Hypertext Transfer Protocol requests between clients and web servers, classifying them and rejecting malicious requests. This type of (WAF) applications, for the most part, have regular expressions that correspond to general rules and allow detecting malicious requests that follow a pattern contained in them. However, due to the knowledge of these rules by attackers, it is easy to circumvent security and to impersonate a malicious request by an innocuous request. Therefore, in this article, we present a study of different models based on artificial intelligence techniques as Naive Bayes, k-nearest neighbors, support vector machines, and linear regression to test their effectiveness in detecting malicious requests from a synthetic dataset containing more than 100,000 requests. The results obtained show that the implementation of these methods optimize the detection of malicious requests obtaining results between 92% and 99% of success in their classification.
引用
收藏
页数:18
相关论文
共 50 条
  • [21] Web Application Firewall Based on Anomaly Detection using Deep Learning
    Toprak, Sezer
    Yavuz, Ali Gokhan
    ACTA INFOLOGICA, 2022, 6 (02): : 219 - 244
  • [22] Improving Efficiency of Web Application Firewall to Detect Code Injection Attacks with Random Forest Method and Analysis Attributes HTTP Request
    Nguyen Manh Thang
    PROGRAMMING AND COMPUTER SOFTWARE, 2020, 46 (05) : 351 - 361
  • [23] Improving Efficiency of Web Application Firewall to Detect Code Injection Attacks with Random Forest Method and Analysis Attributes HTTP Request
    Nguyen Manh Thang
    Programming and Computer Software, 2020, 46 : 351 - 361
  • [24] 应对WEB攻击的防护盲点——WEB Application Firewall
    秦波
    网络安全技术与应用, 2009, (11) : 6 - 9
  • [25] Web Application Attacks Detection Using Deep Learning
    Montes, Nicolas
    Betarte, Gustavo
    Martinez, Rodrigo
    Pardo, Alvaro
    PROGRESS IN PATTERN RECOGNITION, IMAGE ANALYSIS, COMPUTER VISION, AND APPLICATIONS, CIARP 2021, 2021, 12702 : 227 - 236
  • [26] Web Application Firewall Using Machine Learning
    Rohith
    Athief, Ridhwan
    Kishore, Naveen
    Paranthaman, R. Nithya
    2024 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATION AND APPLIED INFORMATICS, ACCAI 2024, 2024,
  • [27] Machine Learning Based Web Application Firewall
    Isiker, Batuhan
    Sogukpinar, Ibrahim
    2ND INTERNATIONAL INFORMATICS AND SOFTWARE ENGINEERING CONFERENCE (IISEC), 2021,
  • [28] AN ANOMALY-BASED WEB APPLICATION FIREWALL
    Torrano-Gimenez, Carmen
    Perez-Villegas, Alejandro
    Alvarez, Gonzalo
    SECRYPT 2009: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2009, : 23 - 28
  • [29] Learning Web Application Firewall - Benefits and Caveats
    Palka, Dariusz
    Zachara, Marek
    AVAILABILITY, RELIABILITY AND SECURITY FOR BUSINESS, ENTERPRISE AND HEALTH INFORMATION SYSTEMS, 2011, 6908 : 295 - 308
  • [30] OwlEye: An Advanced Detection System of Web Attacks Based on HMM
    Liu, Xin
    Yu, Qingchen
    Zhou, Xiaokang
    Zhou, Qingguo
    2018 16TH IEEE INT CONF ON DEPENDABLE, AUTONOM AND SECURE COMP, 16TH IEEE INT CONF ON PERVAS INTELLIGENCE AND COMP, 4TH IEEE INT CONF ON BIG DATA INTELLIGENCE AND COMP, 3RD IEEE CYBER SCI AND TECHNOL CONGRESS (DASC/PICOM/DATACOM/CYBERSCITECH), 2018, : 200 - 207