Improving Web Application Firewalls to detect advanced SQL injection attacks

Improving Web Application Firewalls to detect advanced SQL injection attacks
复制标题

改进 Web 应用程序防火墙以检测高级 SQL 注入攻击

DOI:
10.1109/isias.2014.7064617
复制
发表时间:
2014
期刊:
2014 10th International Conference on Information Assurance and Security
影响因子:
--
通讯作者:
A. Serhrouchni
A. Serhrouchni
中科院分区:
--
文献类型:
--
作者:
Abdelhamid Makiou;Y. Begriche;A. Serhrouchni

文献摘要

被引文献

相似文献

包括SQL注入在内的注入漏洞是影响Web应用程序的最普遍的安全威胁[1]。为了减轻这些攻击,Web应用程序防火墙(WAF)应用安全规则,以便检查HTTP数据流并检测恶意HTTP事务。然而,攻击者可以通过使用复杂的SQL注入技术绕过WAF的规则。在本文中,我们介绍了一种新的方法来剖析HTTP流量和检查复杂的SQL注入攻击。我们的模型是一个混合注射预防系统(HIPS),它使用机器学习分类器和模式匹配检查引擎的基础上减少了安全规则集。我们的Web应用程序防火墙架构旨在通过使用预测模块来优化检测性能,该模块将合法请求排除在检查过程之外。
Injections flaws which include SQL injection are the most prevalent security threats affecting Web applications[1]. To mitigate these attacks, Web Application Firewalls (WAFs) apply security rules in order to both inspect HTTP data streams and detect malicious HTTP transactions. Nevertheless, attackers can bypass WAF's rules by using sophisticated SQL injection techniques. In this paper, we introduce a novel approach to dissect the HTTP traffic and inspect complex SQL injection attacks. Our model is a hybrid Injection Prevention System (HIPS) which uses both a machine learning classifier and a pattern matching inspection engine based on reduced sets of security rules. Our Web Application Firewall architecture aims to optimize detection performances by using a prediction module that excludes legitimate requests from the inspection process.