作者
Abdelhamid Makiou, Youcef Begriche, Ahmed Serhrouchni
发表日期
2014/11/28
研讨会论文
2014 10th international conference on information assurance and security
页码范围
35-40
出版商
IEEE
简介
Injections flaws which include SQL injection are the most prevalent security threats affecting Web applications[1]. To mitigate these attacks, Web Application Firewalls (WAFs) apply security rules in order to both inspect HTTP data streams and detect malicious HTTP transactions. Nevertheless, attackers can bypass WAF's rules by using sophisticated SQL injection techniques. In this paper, we introduce a novel approach to dissect the HTTP traffic and inspect complex SQL injection attacks. Our model is a hybrid Injection Prevention System (HIPS) which uses both a machine learning classifier and a pattern matching inspection engine based on reduced sets of security rules. Our Web Application Firewall architecture aims to optimize detection performances by using a prediction module that excludes legitimate requests from the inspection process.
引用总数
201520162017201820192020202120222023202444283951251
学术搜索中的文章
A Makiou, Y Begriche, A Serhrouchni - 2014 10th international conference on information …, 2014