通过ModSecurity自定义规则发现和缓解Web应用程序漏洞的框架

Trapti Jain, Nakul Jain
{"title":"通过ModSecurity自定义规则发现和缓解Web应用程序漏洞的框架","authors":"Trapti Jain, Nakul Jain","doi":"10.1109/SPIN.2019.8711673","DOIUrl":null,"url":null,"abstract":"In the current era, Digitization has taken day-to-day utilities starting from a cab to grossary on the internet. All the service providers heavily leverage IT and IT Services. Web Application plays a significant role in providing these services. While Digital opens infinite opportunities to increase business and enhance delivery, it also exposes business to an unseen world of cyber-attacks. To prevent the business from digital dysfunctioning, organizations pro-actively and continuously perform Vulnerability Assessments & Penetration Tests on their IT Assets (i.e. Web Applications, Network Devices, Servers, Security Devices, etc.). However, quite often such scans become time consuming and generate unreliable results and none of the tools can find out the effective vulnerability. However, with a set of combined tools in one framework, it is possible to increase the coverage of vulnerability issues. The aim of the research is to present two approaches: (1) Web application vulnerability discovery through a set of web application vulnerability scanners and its integration on the same framework (python as scripting engine) using multi-threading technique (to reduce the scan time). (2) Mitigation of the detected web application vulnerabilities by customizing configuration rules through web application firewall ModSecurity.","PeriodicalId":344030,"journal":{"name":"2019 6th International Conference on Signal Processing and Integrated Networks (SPIN)","volume":"55 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-03-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":"{\"title\":\"Framework for Web Application Vulnerability Discovery and Mitigation by Customizing Rules Through ModSecurity\",\"authors\":\"Trapti Jain, Nakul Jain\",\"doi\":\"10.1109/SPIN.2019.8711673\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In the current era, Digitization has taken day-to-day utilities starting from a cab to grossary on the internet. All the service providers heavily leverage IT and IT Services. Web Application plays a significant role in providing these services. While Digital opens infinite opportunities to increase business and enhance delivery, it also exposes business to an unseen world of cyber-attacks. To prevent the business from digital dysfunctioning, organizations pro-actively and continuously perform Vulnerability Assessments & Penetration Tests on their IT Assets (i.e. Web Applications, Network Devices, Servers, Security Devices, etc.). However, quite often such scans become time consuming and generate unreliable results and none of the tools can find out the effective vulnerability. However, with a set of combined tools in one framework, it is possible to increase the coverage of vulnerability issues. The aim of the research is to present two approaches: (1) Web application vulnerability discovery through a set of web application vulnerability scanners and its integration on the same framework (python as scripting engine) using multi-threading technique (to reduce the scan time). (2) Mitigation of the detected web application vulnerabilities by customizing configuration rules through web application firewall ModSecurity.\",\"PeriodicalId\":344030,\"journal\":{\"name\":\"2019 6th International Conference on Signal Processing and Integrated Networks (SPIN)\",\"volume\":\"55 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-03-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"7\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2019 6th International Conference on Signal Processing and Integrated Networks (SPIN)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/SPIN.2019.8711673\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 6th International Conference on Signal Processing and Integrated Networks (SPIN)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SPIN.2019.8711673","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7

摘要

在当今时代,数字化已经影响了从出租车到互联网上的日常公用事业。所有的服务提供商都大量利用IT和IT服务。Web应用程序在提供这些服务方面起着重要的作用。虽然数字化为增加业务和加强交付提供了无限的机会,但它也将企业暴露在一个看不见的网络攻击世界中。为了防止业务出现数字功能障碍,组织主动并持续地对其IT资产(即Web应用程序、网络设备、服务器、安全设备等)执行漏洞评估和渗透测试。然而,这种扫描往往会耗费大量时间,产生不可靠的结果,而且没有一种工具能够找到有效的漏洞。然而,使用一个框架中的一组组合工具,可以增加漏洞问题的覆盖范围。研究的目的是提出两种方法:(1)通过一组Web应用程序漏洞扫描器发现Web应用程序漏洞,并使用多线程技术将其集成在同一框架(python作为脚本引擎)上(以减少扫描时间)。(2)通过web应用防火墙ModSecurity自定义配置规则,缓解检测到的web应用漏洞。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Framework for Web Application Vulnerability Discovery and Mitigation by Customizing Rules Through ModSecurity
In the current era, Digitization has taken day-to-day utilities starting from a cab to grossary on the internet. All the service providers heavily leverage IT and IT Services. Web Application plays a significant role in providing these services. While Digital opens infinite opportunities to increase business and enhance delivery, it also exposes business to an unseen world of cyber-attacks. To prevent the business from digital dysfunctioning, organizations pro-actively and continuously perform Vulnerability Assessments & Penetration Tests on their IT Assets (i.e. Web Applications, Network Devices, Servers, Security Devices, etc.). However, quite often such scans become time consuming and generate unreliable results and none of the tools can find out the effective vulnerability. However, with a set of combined tools in one framework, it is possible to increase the coverage of vulnerability issues. The aim of the research is to present two approaches: (1) Web application vulnerability discovery through a set of web application vulnerability scanners and its integration on the same framework (python as scripting engine) using multi-threading technique (to reduce the scan time). (2) Mitigation of the detected web application vulnerabilities by customizing configuration rules through web application firewall ModSecurity.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Data Classification by Reducing Bias of Domain-Oriented Knowledge Based on Data Jackets A Robust Automatic Algorithm for Statistical Analysis and Classification of Lung Auscultations Modified Dispersion Equation for Planar Open Tape Helix Travelling Wave Tube Experimental Analysis of Power Generation for Ultra-Low Power Wireless Sensor Nodes Using Various Coatings on Thermoelectric Energy Harvester A Novel Reconfigurable Patch Antenna with Parasitic Patch
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1