首页> 外文期刊>International Journal of Network Security & Its Applications >Pattern Analysis and Signature Extraction For Intrusion Attacks On Web Services
【24h】

Pattern Analysis and Signature Extraction For Intrusion Attacks On Web Services

机译:Web服务入侵攻击的模式分析和签名提取

获取原文
           

摘要

The increasing popularity of web service technology is attracting hackers and attackers to hack the web services and the servers on which they run. Organizations are therefore facing the challenge of implementing adequate security for Web Services. A major threat is that of intruders which may maliciously try to access the data or services. The automated methods of signature extraction extract the binary pattern blindly resulting in more false positives. In this paper a semi automated approach is proposed to analyze the attacks and generate signatures for web services. For data collection, apart from the conventional SOAP data loggers, honeypots are also used that collect small data which is of high value. To filter out the most suspicious part of the data, SVM based classifier is employed to aid the system administrator. By applying an attack signature algorithm on the filtered data, a more balanced attack signature is extracted that results in fewer false positives and negatives. It helps the Security Administrator to identify the web services that are vulnerable or are attacked more frequently.
机译:Web服务技术的日益普及正在吸引黑客和攻击者入侵Web服务及其运行所在的服务器。因此,组织面临着为Web服务实现足够的安全性的挑战。主要威胁在于入侵者可能恶意尝试访问数据或服务。签名提取的自动方法盲目提取二进制模式,从而导致更多的误报。在本文中,提出了一种半自动化方法来分析攻击并生成Web服务的签名。对于数据收集,除了常规的SOAP数据记录器外,还使用蜜罐收集有价值的小数据。为了过滤掉数据中最可疑的部分,使用了基于SVM的分类器来帮助系统管理员。通过对过滤后的数据应用攻击签名算法,可以提取更加平衡的攻击签名,从而减少误报和误报。它可以帮助安全管理员识别易受攻击或受到攻击的Web服务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号