Detecting Web Application Attacks With Use of Gene Expression Programming

被引:3
|
作者
Skaruz, Jaroslaw [1 ]
Seredynski, Franciszek [2 ]
机构
[1] Univ Podlasie, Inst Comp Sci, Sienkiewicza 51, PL-08110 Siedlce, Poland
[2] Polish Acad Sci, Polish Japanese Inst Informat Technol, PL-00901 Warsaw, Poland
来源
2009 IEEE CONGRESS ON EVOLUTIONARY COMPUTATION, VOLS 1-5 | 2009年
关键词
D O I
10.1109/CEC.2009.4983190
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In the paper we present a novel approach based on applying a modern metaheuristic Gene Expression Programming (GEP) to detecting web application attacks. This class of attacks relates to malicious activity of an intruder against applications, which use a database for storing data. The application uses SQL to retrieve data from the database and web server mechanisms to put them in a web browser. A poor implementation allows an attacker to modify SQL statements originally developed by a programmer, which leads to stealing or modifying data to which the attacker has not privileges. While the attack consists in modification of SQL queries sent to the database, they are the only one source of information used for detecting attacks. Intrusion detection problem is transformed into classification problem, which the objective is to classify SQL queries between either normal or malicious queries. GEP is used to find a function used for classification of SQL queries. Experimental results are presented on the basis of SQL queries of different length. The findings show that the efficiency of detecting SQL statements representing attacks depends on the length of SQL statements. Additionally we studied the impact of classification threshold on the obtained results.
引用
收藏
页码:2029 / +
页数:2
相关论文
共 50 条
  • [1] Web Application Security through Gene Expression Programming
    Skaruz, Jaroslaw
    Seredynski, Franciszek
    APPLICATIONS OF EVOLUTIONARY COMPUTING, PROCEEDINGS, 2009, 5484 : 1 - +
  • [2] Advanced Hybrid Technique in Detecting Cloud Web Application's Attacks
    Amar, Meryem
    Lemoudden, Mouad
    El Ouahidi, Bouabid
    MACHINE LEARNING FOR NETWORKING, 2019, 11407 : 79 - 97
  • [3] LSTM Neural Networks for Detecting Anomalies Caused by Web Application Cyber Attacks
    Kotenko, Igor
    Lauta, Oleg
    Kribel, Kseniya
    Saenko, Igor
    NEW TRENDS IN INTELLIGENT SOFTWARE METHODOLOGIES, TOOLS AND TECHNIQUES, 2021, 337 : 127 - 140
  • [4] Web application attacks
    Isotoma Ltd, UK Honeynet Project
    Netw. Secur., 2007, 10 (10-14):
  • [5] Detecting Attacks on Web Applications using Autoencoder
    Hieu Mac
    Dung Truong
    Lam Nguyen
    Hoa Nguyen
    Hai Anh Tran
    Duc Tran
    PROCEEDINGS OF THE NINTH INTERNATIONAL SYMPOSIUM ON INFORMATION AND COMMUNICATION TECHNOLOGY (SOICT 2018), 2018, : 416 - 421
  • [6] Detecting IoT Zombie Attacks on Web Servers
    Sivabalan, Sujatha
    Radcliffe, P. J.
    2017 27TH INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), 2017, : 280 - 282
  • [7] Application of Gene Expression Programming to Real Parameter Optimization
    Xu, Kaikuo
    Tang, Changjie
    Tang, Rong
    Liu, Yintian
    Zuo, Jie
    Zhu, Jun
    ICNC 2008: FOURTH INTERNATIONAL CONFERENCE ON NATURAL COMPUTATION, VOL 6, PROCEEDINGS, 2008, : 273 - +
  • [8] Application of Gene Expression Programming in Lithology Identification and Classification
    Xiao, Fan
    Chen, Jianguo
    Wang, Chengbin
    2012 INTERNATIONAL CONFERENCE ON INTELLIGENCE SCIENCE AND INFORMATION ENGINEERING, 2012, 20 : 196 - 200
  • [9] Increasing Web Service Availability by Detecting Application-Layer DDoS Attacks in Encrypted Traffic
    Zolotukhin, Mikhail
    Hamalainen, Timo
    Kokkonen, Tero
    Siltanen, Jarmo
    2016 23RD INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS (ICT), 2016,
  • [10] Web Application Firewall for Detecting and Mitigation of Based DDoS Attacks Using Machine Learning and Blockchain
    Leka, Elva
    Lamani, Luis
    Aliti, Admirim
    Hoxha, Enkeleda
    TEM JOURNAL-TECHNOLOGY EDUCATION MANAGEMENT INFORMATICS, 2024, 13 (04): : 2802 - 2811