Artificial Intelligent Web Application Firewall for advanced detection of web injection attacks

被引:0
|
作者
Roman-Gallego, Jesus-Angel [1 ]
Perez-Delgado, Maria-Luisa [1 ]
Vinuela, Marcos Luengo [1 ]
Vega-Hernandez, Maria-Concepcion [1 ]
机构
[1] Univ Salamanca, Escuela Politecn Super Zamora, Ave Requejo 33, Zamora 49022, Spain
关键词
artificial intelligence; injection; machine learning; vulnerability; web application firewall; LINEAR-REGRESSION; CLASSIFICATION; MODEL;
D O I
10.1111/exsy.13505
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Currently, web services-based applications have an important presence in public and private organizations. The vulnerabilities that these types of applications may have pose an inherent potential risk to the business model of these organizations. These applications have the inherent risk of being used by organizations in such a way that their activity is affected and they become the main entry point for attackers who want to breach their security. The main barrier to this type of attack are web application firewalls (WAF), which are responsible for processing Hypertext Transfer Protocol requests between clients and web servers, classifying them and rejecting malicious requests. This type of (WAF) applications, for the most part, have regular expressions that correspond to general rules and allow detecting malicious requests that follow a pattern contained in them. However, due to the knowledge of these rules by attackers, it is easy to circumvent security and to impersonate a malicious request by an innocuous request. Therefore, in this article, we present a study of different models based on artificial intelligence techniques as Naive Bayes, k-nearest neighbors, support vector machines, and linear regression to test their effectiveness in detecting malicious requests from a synthetic dataset containing more than 100,000 requests. The results obtained show that the implementation of these methods optimize the detection of malicious requests obtaining results between 92% and 99% of success in their classification.
引用
收藏
页数:18
相关论文
共 50 条
  • [41] Automated Classification of Web-Application Attacks for Intrusion Detection
    Bhagwani, Harsh
    Negi, Rohit
    Dutta, Aneet Kumar
    Handa, Anand
    Kumar, Nitesh
    Shukla, Sandeep Kumar
    SECURITY, PRIVACY, AND APPLIED CRYPTOGRAPHY ENGINEERING, SPACE 2019, 2019, 11947 : 123 - 141
  • [42] Web Application Attacks Detection Using Machine Learning Techniques
    Betarte, Gustavo
    Martinez, Rodrigo
    Pardo, Alvaro
    2018 17TH IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLICATIONS (ICMLA), 2018, : 1065 - 1072
  • [43] Web application security by SQL injection detection tools
    Tajpour, A., 2012, International Journal of Computer Science Issues (IJCSI) (09): : 2 - 3
  • [44] Web Application Firewall: Network Security Models and Configuration
    Clincy, Victor
    Shahriar, Hossain
    2018 IEEE 42ND ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), VOL 1, 2018, : 835 - 836
  • [45] Advanced Hybrid Technique in Detecting Cloud Web Application's Attacks
    Amar, Meryem
    Lemoudden, Mouad
    El Ouahidi, Bouabid
    MACHINE LEARNING FOR NETWORKING, 2019, 11407 : 79 - 97
  • [46] Improving Security of Web-Based Application Using ModSecurity and Reverse Proxy in Web Application Firewall
    Muzaki, Rizki Agung
    Briliyant, Obrina Candra
    Hasditama, Maulana Andika
    Ritchi, Hamzah
    2020 5TH INTERNATIONAL WORKSHOP ON BIG DATA AND INFORMATION SECURITY (IWBIS 2020), 2020, : 89 - 94
  • [47] Mitigation from SQL Injection Attacks on Web Server using Open Web Application Security Project Framework
    Fadlil, A.
    Riadi, I.
    Mu'min, M. A.
    INTERNATIONAL JOURNAL OF ENGINEERING, 2024, 37 (04): : 635 - 645
  • [48] Prediction of SQL Injection Attacks in Web Applications
    Arumugam, Chamundeswari
    Dwarakanathan, Varsha Bhargavi
    Gnanamary, S.
    Neyveli, Vishalraj Natarajan
    Ramesh, Rohit Kanakuppaliyalil
    Kandhavel, Yeshwanthraa
    Balakrishnan, Sadhanandhan
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS, ICCSA 2019, PT IV, 2019, 11622 : 496 - 505
  • [49] The essence of command injection attacks in web applications
    Su, ZD
    Wassermann, G
    ACM SIGPLAN NOTICES, 2006, 41 (01) : 372 - 382
  • [50] Ontology for attack detection: An intelligent approach to web application security
    Razzaq, Abdul
    Anwar, Zahid
    Ahmad, H. Farooq
    Latif, Khalid
    Munir, Faisal
    COMPUTERS & SECURITY, 2014, 45 : 124 - 146