Skip to Main content Skip to Navigation
Journal articles

An Invariant-based Approach for Detecting Attacks against Data in Web Applications

Romaric Ludinard 1 Eric Totel 1 Frédéric Tronel 1 Vincent Nicomette 2 Mohamed Kaâniche 2 Eric Alata 2 Rim Akrout 2 Yann Bachy 2
1 CIDRE - Confidentialité, Intégrité, Disponibilité et Répartition
IRISA-D1 - SYSTÈMES LARGE ÉCHELLE, Inria Rennes – Bretagne Atlantique , CentraleSupélec
2 LAAS-TSF - Équipe Tolérance aux fautes et Sûreté de Fonctionnement informatique
LAAS - Laboratoire d'analyse et d'architecture des systèmes
Abstract : RRABIDS (Ruby on Rails Anomaly Based Intrusion Detection System) is an application levelintrusion detection system (IDS) for applications implemented with the Ruby on Railsframework. The goal of this intrusion detection system is to detect attacks against data in thecontext of web applications. This anomaly based IDS focuses on the modelling of the normalapplication profile using invariants. These invariants are discovered during a learning phase.Then, they are used to instrument the web application at source code level, so that a deviationfrom the normal profile can be detected at run-time. This paper illustrates on simple exampleshow the approach detects well-known categories of web attacks that involve a state violation ofthe application, such as SQL injections. Finally, an assessment phase is performed to evaluatethe accuracy of the detection provided by the proposed approach.
Document type :
Journal articles
Complete list of metadata

Cited literature [18 references]  Display  Hide  Download
Contributor : Frédéric Tronel Connect in order to contact the contributor
Submitted on : Monday, November 17, 2014 - 9:26:14 AM
Last modification on : Tuesday, October 19, 2021 - 11:58:55 PM
Long-term archiving on: : Friday, April 14, 2017 - 1:54:15 PM


Files produced by the author(s)



Romaric Ludinard, Eric Totel, Frédéric Tronel, Vincent Nicomette, Mohamed Kaâniche, et al.. An Invariant-based Approach for Detecting Attacks against Data in Web Applications. International journal of secure software engineering, IGI Global, 2014, 5 (1), pp.19-38. ⟨10.4018/ijsse.2014010102⟩. ⟨hal-01083296⟩



Les métriques sont temporairement indisponibles