Deep Learning Technique-Enabled Web Application Firewall for the Detection of Web Attacks

被引:19
作者
Dawadi, Babu R. [1 ]
Adhikari, Bibek [1 ]
Srivastava, Devesh K. [2 ]
机构
[1] Tribhuvan Univ, Dept Elect & Comp Engn, Pulchowk Campus, Kathmandu 19758, Nepal
[2] Manipal Univ, Dept Informat Technol, Jaypur 303007, India
关键词
WAF; LSTM; XSS; SQL injection; web security;
D O I
10.3390/s23042073
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
New techniques and tactics are being used to gain unauthorized access to the web that harm, steal, and destroy information. Protecting the system from many threats such as DDoS, SQL injection, cross-site scripting, etc., is always a challenging issue. This research work makes a comparative analysis between normal HTTP traffic and attack traffic that identifies attack-indicating parameters and features. Different features of standard datasets ISCX, CISC, and CICDDoS were analyzed and attack and normal traffic were compared by taking different parameters into consideration. A layered architecture model for DDoS, XSS, and SQL injection attack detection was developed using a dataset collected from the simulation environment. In the long short-term memory (LSTM)-based layered architecture, the first layer was the DDoS detection model designed with an accuracy of 97.57% and the second was the XSS and SQL injection layer with an obtained accuracy of 89.34%. The higher rate of HTTP traffic was investigated first and filtered out, and then passed to the second layer. The web application firewall (WAF) adds an extra layer of security to the web application by providing application-level filtering that cannot be achieved by the traditional network firewall system.
引用
收藏
页数:16
相关论文
共 27 条
[1]   Deep Learning for Vulnerability and Attack Detection on Web Applications: A Systematic Literature Review [J].
Alaoui, Rokia Lamrani ;
Nfaoui, El Habib .
FUTURE INTERNET, 2022, 14 (04)
[2]   Refined LSTM Based Intrusion Detection for Denial-of-Service Attack in Internet of Things [J].
Alimi, Kuburat Oyeranti Adefemi ;
Ouahada, Khmaies ;
Abu-Mahfouz, Adnan M. ;
Rimer, Suvendi ;
Alimi, Oyeniyi Akeem .
JOURNAL OF SENSOR AND ACTUATOR NETWORKS, 2022, 11 (03)
[3]   A Machine-Learning-Driven Evolutionary Approach for Testing Web Application Firewalls [J].
Appelt, Dennis ;
Nguyen, Cu D. ;
Panichella, Annibale ;
Briand, Lionel C. .
IEEE TRANSACTIONS ON RELIABILITY, 2018, 67 (03) :733-757
[4]   Web Application Firewall: Network Security Models and Configuration [J].
Clincy, Victor ;
Shahriar, Hossain .
2018 IEEE 42ND ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), VOL 1, 2018, :835-836
[5]  
Gimenez C.T., 2010, HTTP DATA SET CSIC 2, V64
[6]   Web Application Security: Threats, Countermeasures, and Pitfalls [J].
Huang, Hsiu-Chuan ;
Zhang, Zhi-Kai ;
Cheng, Hao-Wen ;
Shieh, Shiuhpyng Winston .
COMPUTER, 2017, 50 (06) :81-85
[7]  
Ito M, 2018, 2018 IEEE 14TH INTERNATIONAL COLLOQUIUM ON SIGNAL PROCESSING & ITS APPLICATIONS (CSPA 2018), P103, DOI 10.1109/CSPA.2018.8368694
[8]  
Jakic P., 2019, P SINTEZA 2019 INT S, P155
[9]   A Novel Data Augmentation Technique and Deep Learning Model for Web Application Security [J].
Karacan, Hacer ;
Sevri, Mehmet .
IEEE ACCESS, 2021, 9 :150781-150797
[10]   LSTM Neural Networks for Detecting Anomalies Caused by Web Application Cyber Attacks [J].
Kotenko, Igor ;
Lauta, Oleg ;
Kribel, Kseniya ;
Saenko, Igor .
NEW TRENDS IN INTELLIGENT SOFTWARE METHODOLOGIES, TOOLS AND TECHNIQUES, 2021, 337 :127-140