Title :
On the Automated Creation of Understandable Positive Security Models for Web Applications
Author :
Bockermann, Christian ; Mierswa, Ingo ; Morik, Katharina
Author_Institution :
Dept. of Comput. Sci., Univ. of Dortmund, Dortmund
Abstract :
Web applications pose new security-related challenges since attacks on web applications strongly differ from those on client-server applications. Traditional network-based firewall systems offer no protection against this kind of attacks since they occur on the application-level. The current solution is the manual definition of large sets of filtering rules which should prevent malicious attempts from being successful. We propose a new framework which should avoid this tedious work. The basic idea is the definition of a description language for positive security models taking the particularities of web applications into account. We then present adaptive techniques which employ this description language in order to describe the valid communication to a given web application. The simplicity of the description language allows the easy identification of unintentionally incorporated vulnerabilities. Experiments for several real- world web applications demonstrate the usefulness of the proposed approach.
Keywords :
Internet; security of data; Web application; description language; network-based firewall system; security model; Application software; Data mining; Data security; Databases; Information filtering; Information filters; Intrusion detection; Law; Legal factors; Web server;
Conference_Titel :
Pervasive Computing and Communications, 2008. PerCom 2008. Sixth Annual IEEE International Conference on
Conference_Location :
Hong Kong
Print_ISBN :
978-0-7695-3113-7
DOI :
10.1109/PERCOM.2008.59