Detecting Web Application Attacks With Use of Gene Expression Programming

被引:3
作者
Skaruz, Jaroslaw [1 ]
Seredynski, Franciszek [2 ]
机构
[1] Univ Podlasie, Inst Comp Sci, Sienkiewicza 51, PL-08110 Siedlce, Poland
[2] Polish Acad Sci, Polish Japanese Inst Informat Technol, PL-00901 Warsaw, Poland
来源
2009 IEEE CONGRESS ON EVOLUTIONARY COMPUTATION, VOLS 1-5 | 2009年
关键词
D O I
10.1109/CEC.2009.4983190
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In the paper we present a novel approach based on applying a modern metaheuristic Gene Expression Programming (GEP) to detecting web application attacks. This class of attacks relates to malicious activity of an intruder against applications, which use a database for storing data. The application uses SQL to retrieve data from the database and web server mechanisms to put them in a web browser. A poor implementation allows an attacker to modify SQL statements originally developed by a programmer, which leads to stealing or modifying data to which the attacker has not privileges. While the attack consists in modification of SQL queries sent to the database, they are the only one source of information used for detecting attacks. Intrusion detection problem is transformed into classification problem, which the objective is to classify SQL queries between either normal or malicious queries. GEP is used to find a function used for classification of SQL queries. Experimental results are presented on the basis of SQL queries of different length. The findings show that the efficiency of detecting SQL statements representing attacks depends on the length of SQL statements. Additionally we studied the impact of classification threshold on the obtained results.
引用
收藏
页码:2029 / +
页数:2
相关论文
共 50 条
[21]   Use of Gene Expression Programming in regionalization of flow duration curve [J].
Hashmi, Muhammad Z. ;
Shamseldin, Asaad Y. .
ADVANCES IN WATER RESOURCES, 2014, 68 :1-12
[22]   Categorization of web pages based on HsMM for detecting DDoS attacks [J].
Xie, Yi ;
Yu, Shun-Zheng .
DYNAMICS OF CONTINUOUS DISCRETE AND IMPULSIVE SYSTEMS-SERIES B-APPLICATIONS & ALGORITHMS, 2006, 13E :2330-2335
[23]   DeepWAF: Detecting Web Attacks Based on CNN and LSTM Models [J].
Kuang, Xiaohui ;
Zhang, Ming ;
Li, Hu ;
Zhao, Gang ;
Cao, Huayang ;
Wu, Zhendong ;
Wang, Xianmin .
CYBERSPACE SAFETY AND SECURITY, PT II, 2019, 11983 :121-136
[24]   Detecting web attacks using random undersampling and ensemble learners [J].
Richard Zuech ;
John Hancock ;
Taghi M. Khoshgoftaar .
Journal of Big Data, 8
[25]   Detecting web attacks using random undersampling and ensemble learners [J].
Zuech, Richard ;
Hancock, John ;
Khoshgoftaar, Taghi M. .
JOURNAL OF BIG DATA, 2021, 8 (01)
[26]   Detecting Web Attacks in Severely Imbalanced Network Traffic Data [J].
Zuech, Richard ;
Hancock, John ;
Khoshgoftaar, Taghi M. .
2021 IEEE 22ND INTERNATIONAL CONFERENCE ON INFORMATION REUSE AND INTEGRATION FOR DATA SCIENCE (IRI 2021), 2021, :267-273
[27]   Detecting web attacks with end-to-end deep learning [J].
Pan, Yao ;
Sun, Fangzhou ;
Teng, Zhongwei ;
White, Jules ;
Schmidt, Douglas C. ;
Staples, Jacob ;
Krause, Lee .
JOURNAL OF INTERNET SERVICES AND APPLICATIONS, 2019, 10 (01)
[28]   Phantasus, a web application for visual and interactive gene expression analysis [J].
Kleverov, Maksim ;
Zenkova, Daria ;
Kamenev, Vladislav ;
Sablina, Margarita ;
Artyomov, Maxim N. ;
Sergushichev, Alexey A. .
ELIFE, 2024, 13
[29]   Genealyzer: web application for the analysis and comparison of gene expression data [J].
Kristina Lietz ;
Babak Saremi ;
Lena Wiese .
BMC Bioinformatics, 24
[30]   Spotivey: A web application for simplified use of the Spotify application programming interface in online questionnaire studies [J].
Radke, Markus ;
Lepa, Steffen ;
Ladleif, Matthias .
MOBILE MEDIA & COMMUNICATION, 2024, 12 (02) :441-445