AppMine: Behavioral Analytics for Web Application Vulnerability Detection

AppMine: Behavioral Analytics for Web Application Vulnerability Detection
复制标题

AppMine:用于 Web 应用程序漏洞检测的行为分析

DOI:
10.1145/3338466.3358923
复制
发表时间:
2019
期刊:
The ACM Cloud Computing Security Workshop (CCSW
影响因子:
--
通讯作者:
Oprea, Alina
Oprea, Alina
中科院分区:
--
文献类型:
--
作者:
Jana, Indranil;Oprea, Alina

文献摘要

参考文献

被引文献

相似文献

广泛使用的Web应用程序一直是大规模攻击的目标,导致服务大规模中断和经济损失,就像Equifax数据泄露事件一样。将Web应用部署在像Docker这样的容器中已经成为一种常见的做法,以实现更好的可移植性和部署的简便性。我们设计了一个名为Appmy的系统,用于轻量级地监控运行在Docker容器中的Web应用程序,并检测未知的Web漏洞。Appmine是一种无监督学习系统,仅对Web应用程序的合法工作负载进行训练,以基于传统模型(PCA和单类支持向量机)或更高级的神经网络结构(LSTM)检测异常。在我们的评估中,我们证明了神经网络模型在一系列Web应用程序和重新创建的利用漏洞方面的表现优于更传统的方法。例如,Appmine在ApacheStruts应用程序(利用Equifax漏洞中使用的CVE-2017-5638漏洞)的平均AUC得分高达0.97,而PCA和One-Class SVM的AUC得分分别为0.81和0.83。
Web applications in widespread use have always been the target of large-scale attacks, leading to massive disruption of services and financial loss, as in the Equifax data breach. It has become common practice to deploy web applications in containers like Docker for better portability and ease of deployment. We design a system called AppMine for lightweight monitoring of web applications running in Docker containers and detection of unknown web vulnerabilities. AppMine is an unsupervised learning system, trained only on legitimate workloads of web applications, to detect anomalies based on either traditional models (PCA and one-class SVM), or more advanced neural-network architectures (LSTM). In our evaluation, we demonstrate that the neural network model outperforms more traditional methods on a range of web applications and recreated exploits. For instance, AppMine achieves average AUC scores as high as 0.97 for the Apache Struts application (with the CVE-2017-5638 exploit used in the Equifax breach), while the AUC scores for PCA and one-class SVM are 0.81 and 0.83, respectively.
使用函数调用序列分析计算机入侵
DOI: 10.1109/tdsc.2007.1003
发表时间: 2007
影响因子: 7.3
作者:
S. Peisert;M. Bishop;Sidney Karin;K. Marzullo
通讯作者: K. Marzullo
DOI: 10.1088/1475-7516/2017/10/052
发表时间: 2017
影响因子: 6.4
作者:
J. Luis Bernal;N. Bellomo;A. Raccanelli;L. Verde
通讯作者: L. Verde
DOI: 10.14722/ndss.2018.23141
发表时间: 2018
期刊: --
影响因子: --
作者:
Wajih Ul Hassan;Mark Lemay;Nuraini Aguse;Adam Bates;Thomas Moyer
通讯作者: Wajih Ul Hassan;Mark Lemay;Nuraini Aguse;Adam Bates;Thomas Moyer
对系统调用计数向量序列的进程监控
DOI: 10.1109/ccst.2017.8167792
发表时间: 2017
期刊: 2017 International Carnahan Conference on Security Technology (ICCST)
影响因子: --
作者:
M. Dymshits;Benjamin Myara;David Tolpin
通讯作者: David Tolpin
DOI: 10.1145/3243734.3243776
发表时间: 2018-01
期刊: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Thomas Pasquier;Xueyuan Han;Thomas Moyer;Adam Bates;O. Hermant;D. Eyers;J. Bacon;M. Seltzer
通讯作者: Thomas Pasquier;Xueyuan Han;Thomas Moyer;Adam Bates;O. Hermant;D. Eyers;J. Bacon;M. Seltzer