Artificial Intelligent Web Application Firewall for advanced detection of web injection attacks

被引:0
|
作者
Roman-Gallego, Jesus-Angel [1 ]
Perez-Delgado, Maria-Luisa [1 ]
Vinuela, Marcos Luengo [1 ]
Vega-Hernandez, Maria-Concepcion [1 ]
机构
[1] Univ Salamanca, Escuela Politecn Super Zamora, Ave Requejo 33, Zamora 49022, Spain
关键词
artificial intelligence; injection; machine learning; vulnerability; web application firewall; LINEAR-REGRESSION; CLASSIFICATION; MODEL;
D O I
10.1111/exsy.13505
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Currently, web services-based applications have an important presence in public and private organizations. The vulnerabilities that these types of applications may have pose an inherent potential risk to the business model of these organizations. These applications have the inherent risk of being used by organizations in such a way that their activity is affected and they become the main entry point for attackers who want to breach their security. The main barrier to this type of attack are web application firewalls (WAF), which are responsible for processing Hypertext Transfer Protocol requests between clients and web servers, classifying them and rejecting malicious requests. This type of (WAF) applications, for the most part, have regular expressions that correspond to general rules and allow detecting malicious requests that follow a pattern contained in them. However, due to the knowledge of these rules by attackers, it is easy to circumvent security and to impersonate a malicious request by an innocuous request. Therefore, in this article, we present a study of different models based on artificial intelligence techniques as Naive Bayes, k-nearest neighbors, support vector machines, and linear regression to test their effectiveness in detecting malicious requests from a synthetic dataset containing more than 100,000 requests. The results obtained show that the implementation of these methods optimize the detection of malicious requests obtaining results between 92% and 99% of success in their classification.
引用
收藏
页数:18
相关论文
共 50 条
  • [31] Method of developing a web-application firewall
    Khamdamov R.K.
    Kerimov K.F.
    Ibrahimov J.O.
    Journal of Automation and Information Sciences, 2019, 51 (06) : 65 - 74
  • [32] Web Application Firewall for Detecting and Mitigation of Based DDoS Attacks Using Machine Learning and Blockchain
    Leka, Elva
    Lamani, Luis
    Aliti, Admirim
    Hoxha, Enkeleda
    TEM JOURNAL-TECHNOLOGY EDUCATION MANAGEMENT INFORMATICS, 2024, 13 (04): : 2802 - 2811
  • [33] Intelligent Web-Application for Countering DDoS Attacks on Educational Institutions
    Mikhail, Ivanov
    Victor, Radygin
    Korchagin, Sergey
    Ekaterina, Pleshakova
    Dmitry, Sheludyakov
    Yerbayev, Yerbol
    Konstantin, Bublikov
    BIOLOGICALLY INSPIRED COGNITIVE ARCHITECTURES 2021, 2022, 1032 : 182 - 194
  • [35] Ontology for Detection of Web Attacks
    Khairkar, Ashwini D.
    Kshirsagar, Deepak D.
    Kumar, Sandeep
    2013 INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS AND NETWORK TECHNOLOGIES (CSNT 2013), 2013, : 612 - 615
  • [36] Robust Training for Injection Attacks Detection in Web-based Applications
    Appiah, Benjamin
    Qin, Zhiguang
    Kwabena, Owusu A.
    Abdullah, Muhammed A.
    International Journal of Network Security, 2021, 23 (06) : 1028 - 1036
  • [37] Detection of SQL Injection and XSS Attacks in Three Tier Web Applications
    Sonewar, Piyush A.
    Thosar, Sonali D.
    2016 INTERNATIONAL CONFERENCE ON COMPUTING COMMUNICATION CONTROL AND AUTOMATION (ICCUBEA), 2016,
  • [38] Dynamic Managements of the firewall policy to mitigate DDoS attacks in web services
    Chen Y.-L.
    Chen Y.-C.
    Journal of Convergence Information Technology, 2011, 6 (08) : 292 - 298
  • [39] Dynamic Adjustment of the Firewall Policy to Mitigate DDoS Attacks for Web Services
    Chen, Young-Long
    Chen, Ying-Chen
    2011 INTERNATIONAL CONFERENCE ON COMPUTER, ELECTRICAL, AND SYSTEMS SCIENCES, AND ENGINEERING (CESSE 2011), 2011, : 496 - 499
  • [40] Application of the Generic Feature Selection Measure in Detection of Web Attacks
    Hai Thanh Nguyen
    Torrano-Gimenez, Carmen
    Alvarez, Gonzalo
    Petrovic, Slobodan
    Franke, Katrin
    COMPUTATIONAL INTELLIGENCE IN SECURITY FOR INFORMATION SYSTEMS, 2011, 6694 : 25 - 32