作者
Silvan Zeller, Narges Khakpour, Danny Weyns, Daniel Deogun
发表日期
2020/6/29
图书
Proceedings of the IEEE/ACM 15th International Symposium on Software Engineering for Adaptive and Self-Managing Systems
页码范围
174-180
简介
Attacks against business logic rules occur when the attacker exploits the domain rules in a malicious way. Such attacks have not received sufficient attention in research so far. In this paper, we propose a novel self-protecting approach that defends a system against the exploitation of business logic vulnerabilities. The approach empowers a system with a self-protecting layer to protect it against attacks aimed at misusing business logic rules. The approach maintains up-to-date domain knowledge which is analyzed using runtime verification to detect logical attacks. When attacks are discovered they are dynamically mitigated by applying proper system reconfigurations at runtime. We evaluate the approach using a case from the domain of hotel booking systems.
引用总数
20212022202320241312
学术搜索中的文章
S Zeller, N Khakpour, D Weyns, D Deogun - Proceedings of the IEEE/ACM 15th International …, 2020