首页> 外文期刊>International Journal of Applied Engineering Research >RPAD: Rule based Pattern Discovery for Input Type Validation Vulnerabilities Detection & Prevention of HTTP Requests
【24h】

RPAD: Rule based Pattern Discovery for Input Type Validation Vulnerabilities Detection & Prevention of HTTP Requests

机译:RPAD:基于规则的输入类型验证漏洞的模式发现检测和预防HTTP请求

获取原文
获取原文并翻译 | 示例
           

摘要

The internet access by web browsers is most vulnerable, since the browsers itself can adapt as attacking tool. The traditional way of dealing the influence of these vulnerabilities such as SQL Injections and XSS is the code verification by syntax analyzers. Since the syntax analyzers deployed and executed in server environment, the process overhead on servers is the major constraint observed, which is due to the online verification of dynamic SQL statements generated by web enabled applications and injected into server-side applications. The other major constraint of these syntax analyzers programming language dependency. In order to this here in this paper we proposed a Rule based Pattern Discovery (RPAD) for Input Type Validation Vulnerabilities Detection and Prevention of HTTP Requests. The core objective of the RPAD is to execute as network level IDS and not to rely on syntax analyzers, hence the limits such as programming language dependency and server level process overhead observed in existing benchmarking models are least significant for RPAD. The other competency of RPAD is minimal sanity checks. The experimental study was conducted on several benchmarking CVE entries published by NIST. The combination of 2783 attack patterns extracted from CVE entries of the NIST and 512 normal patterns extracted from 7 real time web applications were used to evince the performance of the RPAD. The empirical study evinced that the RPAD prediction accuracy is around 93%.
机译:Web浏览器的Internet访问是最脆弱的,因为浏览器本身可以适应攻击工具。处理这些漏洞的影响的传统方式,如SQL注入和XSS是语法分析仪的代码验证。由于在服务器环境中部署和执行的语法分析仪,服务器上的进程开销是所观察到的主要约束,这是由于Web启用的应用程序生成的动态SQL语句的在线验证,并注入服务器端应用程序。这些语法分析仪编程语言依赖的其他主要约束。在本文中,我们提出了一种基于规则的模式发现(RPAD),用于输入类型验证漏洞检测和预防HTTP请求。 RPAD的核心目标是执行作为网络级别ID,而不是依赖于语法分析仪,因此在现有基准模型中观察到的编程语言依赖性和服务器级过程开销的限制对于RPAD是最重要的。 RPAD的其他能力是最小的理智检查。实验研究是在NIST发布的几个基准CVE条目上进行的。从NIST和512个正常模式中提取的2783攻击模式的组合用于从7个实时Web应用程序中提取的512正常模式,用于Evcuce对RPAD的性能。实证研究表明,RPAD预测精度约为93%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号