An Invariant-based Approach for Detecting Attacks against Data in Web Applications - Archive ouverte HAL Access content directly
Journal Articles International journal of secure software engineering Year : 2014

An Invariant-based Approach for Detecting Attacks against Data in Web Applications

(1) , (1) , (1) , (2) , (2) , (2) , (2) , (2)
1
2

Abstract

RRABIDS (Ruby on Rails Anomaly Based Intrusion Detection System) is an application levelintrusion detection system (IDS) for applications implemented with the Ruby on Railsframework. The goal of this intrusion detection system is to detect attacks against data in thecontext of web applications. This anomaly based IDS focuses on the modelling of the normalapplication profile using invariants. These invariants are discovered during a learning phase.Then, they are used to instrument the web application at source code level, so that a deviationfrom the normal profile can be detected at run-time. This paper illustrates on simple exampleshow the approach detects well-known categories of web attacks that involve a state violation ofthe application, such as SQL injections. Finally, an assessment phase is performed to evaluatethe accuracy of the detection provided by the proposed approach.
Fichier principal
Vignette du fichier
IJSSE_APA4_def.pdf (641.6 Ko) Télécharger le fichier
Origin : Files produced by the author(s)
Loading...

Dates and versions

hal-01083296 , version 1 (17-11-2014)

Identifiers

Cite

Romaric Ludinard, Eric Totel, Frédéric Tronel, Vincent Nicomette, Mohamed Kaâniche, et al.. An Invariant-based Approach for Detecting Attacks against Data in Web Applications. International journal of secure software engineering, 2014, 5 (1), pp.19-38. ⟨10.4018/ijsse.2014010102⟩. ⟨hal-01083296⟩
519 View
545 Download

Altmetric

Share

Gmail Facebook Twitter LinkedIn More