Detect HTTP Specification Attacks Using Ontology

Rana Faisal Munir, N. Ahmed, Hafiz Abdul Razzaq, Ali Hur, H. F. Ahmad
{"title":"Detect HTTP Specification Attacks Using Ontology","authors":"Rana Faisal Munir, N. Ahmed, Hafiz Abdul Razzaq, Ali Hur, H. F. Ahmad","doi":"10.1109/FIT.2011.21","DOIUrl":null,"url":null,"abstract":"Web applications after their revolutionary advent and popularity are target of variety of attacks. Magnitude and complexity of attacks is continuously growing with every minute development in World Wide Web. There are plenty of web attack detection techniques but they cannot fully comprehend the required degree of security for complex web applications. The reasons include static nature of attack detection mechanism, lack of expressiveness in attack detection rules, and absence of reasoning capability to detect unanticipated ways an attack can be launched. To cater these issues, a formal approach is required that has more expressiveness and equipped with reasoning. These traits are fully adhered to by the Semantic techniques. This paper introduces an approach for utilizing Semantic techniques in web application security. This has never been introduced previously to the best of our knowledge. Here the HTTP Protocol ontology is presented to mitigate the communication protocol attacks. In this paper we are focusing on communication protocol attacks including abnormal HTTP messages, HTTP request smuggling and HTTP response splitting. While dealing with these attacks, the proposed technique outperforms the existing solutions with higher detection rate and low false positives as indicated by evaluation results.","PeriodicalId":101923,"journal":{"name":"2011 Frontiers of Information Technology","volume":"13 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2011-12-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2011 Frontiers of Information Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/FIT.2011.21","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Web applications after their revolutionary advent and popularity are target of variety of attacks. Magnitude and complexity of attacks is continuously growing with every minute development in World Wide Web. There are plenty of web attack detection techniques but they cannot fully comprehend the required degree of security for complex web applications. The reasons include static nature of attack detection mechanism, lack of expressiveness in attack detection rules, and absence of reasoning capability to detect unanticipated ways an attack can be launched. To cater these issues, a formal approach is required that has more expressiveness and equipped with reasoning. These traits are fully adhered to by the Semantic techniques. This paper introduces an approach for utilizing Semantic techniques in web application security. This has never been introduced previously to the best of our knowledge. Here the HTTP Protocol ontology is presented to mitigate the communication protocol attacks. In this paper we are focusing on communication protocol attacks including abnormal HTTP messages, HTTP request smuggling and HTTP response splitting. While dealing with these attacks, the proposed technique outperforms the existing solutions with higher detection rate and low false positives as indicated by evaluation results.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
使用本体检测HTTP规范攻击
Web应用程序在其革命性的出现和流行之后,成为各种攻击的目标。随着万维网的飞速发展,网络攻击的规模和复杂性也在不断增长。有很多web攻击检测技术,但它们不能完全理解复杂web应用程序所需的安全程度。其原因包括攻击检测机制的静态特性、攻击检测规则缺乏表达能力以及缺乏检测意外攻击方式的推理能力。为了解决这些问题,需要一种更有表现力和推理能力的正式方法。语义技术完全遵循了这些特征。本文介绍了语义技术在web应用安全中的应用。据我们所知,以前从未有人介绍过这一点。本文提出了HTTP协议本体来缓解通信协议攻击。本文主要研究了HTTP异常消息、HTTP请求走私和HTTP响应分裂等通信协议攻击。在处理这些攻击时,评估结果表明,该技术具有更高的检测率和低的误报率,优于现有的解决方案。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Quantifying Non-functional Requirements in Service Oriented Development Secure Solution to Data Transfer from Sensor Node to Sink against Aggregator Compromises Development of an Optical Sensor for the Detection of Volatile Organic Compounds Network Performance Optimization: A Case Study of Enterprise Network Simulated in OPNET Fully Distributed Cooperative Spectrum Sensing for Cognitive Radio Ad Hoc Networks
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1