Improving Web Application Firewalls to detect advanced SQL injection attacks
Improving Web Application Firewalls to detect advanced SQL injection attacks
复制标题
改进 Web 应用程序防火墙以检测高级 SQL 注入攻击
DOI:
10.1109/isias.2014.7064617
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
A. Serhrouchni
中科院分区:
文献类型:
--
作者:
Abdelhamid Makiou;Y. Begriche;A. Serhrouchni
Injections flaws which include SQL injection are the most prevalent security threats affecting Web applications[1]. To mitigate these attacks, Web Application Firewalls (WAFs) apply security rules in order to both inspect HTTP data streams and detect malicious HTTP transactions. Nevertheless, attackers can bypass WAF's rules by using sophisticated SQL injection techniques. In this paper, we introduce a novel approach to dissect the HTTP traffic and inspect complex SQL injection attacks. Our model is a hybrid Injection Prevention System (HIPS) which uses both a machine learning classifier and a pattern matching inspection engine based on reduced sets of security rules. Our Web Application Firewall architecture aims to optimize detection performances by using a prediction module that excludes legitimate requests from the inspection process.