DocumentCode
2812652
Title
Web server attack categorization based on root causes and their locations
Author
Seo, Jeongseok ; Kim, Han-Sung ; Cho, Sanghyun ; Cha, Sungdeok
Author_Institution
Dept. of Comput. Sci., KAIST, Daejon, South Korea
Volume
1
fYear
2004
fDate
5-7 April 2004
Firstpage
90
Abstract
Frequency of attacks on Web services and resulting damage continue to grow as Web services become popular. Unfortunately, existing signature-based intrusion detection techniques are inadequate in providing reasonable degree of Web security. Web attacks are diverse in nature, and typical Web architecture consists of complex and hierarchically organized components. Because attack strategies often vary depending on the Web contents, it is impossible to develop fixed patterns capturing unknown attacks. Protection mechanisms such as anomaly-based intrusion detection and application-level IDS, tailored to Web services, are needed to detect Web attacks. The first step in developing Web application IDS is to analyze and categorize possible Web attacks and vulnerabilities. In this paper, we classify Web attacks by analyzing the root causes and the locations where they occur. This research is useful in developing Web IDS modules, tracking emerging trends on Web attacks, and testing Web applications against potential vulnerabilities.
Keywords
Internet; data privacy; file servers; message authentication; pattern classification; telecommunication security; Web IDS modules; Web application IDS; Web architecture; Web attacks; Web contents; Web security; Web server attack categorization; Web services; Web vulnerabilities; World Wide Web; anomaly-based intrusion detection; application-level IDS; attack frequency; attack strategies; complex components; fixed patterns; hierarchically organized components; protection mechanisms; root causes; signature-based intrusion detection; Access control; Computer crashes; Computer science; Frequency conversion; Information security; Intrusion detection; Protection; Service oriented architecture; Web server; Web services;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Technology: Coding and Computing, 2004. Proceedings. ITCC 2004. International Conference on
Print_ISBN
0-7695-2108-8
Type
conf
DOI
10.1109/ITCC.2004.1286431
Filename
1286431
Link To Document