【24h】

Web Application Security through Gene Expression Programming

机译:通过基因表达程序编程Web应用程序安全性

获取原文

摘要

In the paper we present a novel approach based on applying a modern metaheuristic Gene Expression Programming (GEP) to detecting web application attacks. This class of attacks relates to malicious activity of an intruder against applications, which use a database for storing data. The application uses SQL to retrieve data from the database and web server mechanisms to put them in a web browser. A poor implementation allows an attacker to modify SQL statements originally developed by a programmer, which leads to stealing or modifying data to which the attacker has not privileges. Intrusion detection problem is transformed into classification problem, which the objective is to classify SQL queries between either normal or malicious queries. GEP is used to find a function used for classification of SQL queries. Experimental results are presented on the basis of SQL queries of different length. The findings show that the efficiency of detecting SQL statements representing attacks depends on the length of SQL statements.
机译:在本文中,我们提出了一种基于应用现代成群质基因表达编程(GEP)来检测Web应用程序攻击的新方法。这类攻击涉及侵犯应用程序的恶意活动,该应用程序使用数据库来存储数据。应用程序使用SQL从数据库和Web服务器机制中检索数据,以将它们放在Web浏览器中。较差的实现允许攻击者修改由程序员创建的SQL语句,这导致窃取或修改攻击者没有权限的数据。入侵检测问题转换为分类问题,该目标是在正常或恶意查询之间对SQL查询进行分类。 GEP用于找到用于分类SQL查询的函数。实验结果是基于不同长度的SQL查询。调查结果表明,检测代表攻击的SQL语句的效率取决于SQL语句的长度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号