【24h】

Web Application Firewall Evasion Techniques

机译:Web应用程序防火墙规避技术

获取原文

摘要

Recently there has been a robust increase in cyber attacks. Statistical studies show that around 4% of internet traffic is malicious. Firewalls are deployed as blocking mechanisms to identify and prevent malicious requests. They filter seemingly malicious packets based on the filter rules. Despite the filters, there are certain evasion techniques used by attackers to bypass the firewall. This paper describes the techniques for bypassing the web application firewall based on their configurations and paranoia levels of implementation so that security researchers can understand loop holes in the firewall to build a better firewall strategy. By these techniques, an attacker can achieve the attacks he intends to do even if the firewall is placed between the web application and the client.
机译:最近,网络攻击急剧增加。统计研究表明,大约4%的互联网流量是恶意的。防火墙被部署为阻止机制,以识别和阻止恶意请求。它们根据过滤规则过滤看似恶意的数据包。尽管有过滤器,但攻击者仍使用某些逃避技术来绕过防火墙。本文根据其配置和实施的偏执程度描述了绕过Web应用程序防火墙的技术,以便安全研究人员可以了解防火墙中的漏洞以建立更好的防火墙策略。通过这些技术,即使将防火墙放在Web应用程序和客户端之间,攻击者也可以实现他打算进行的攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号