Recent Attack Prevention Techniques in Web Service Applications

被引:0
|
作者
Bherde, Gajanan P. [1 ]
Pund, M. A. [2 ]
机构
[1] KJ Somaiya Coll Engn, Dept Comp Engn, Bombay, Maharashtra, India
[2] PRMIT&R, Dept Comp Sci & Engn, Badnera, Amravati, India
关键词
web applications; attack detection; attack prevention; web security; XML attack;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Internet security is very challenging task because internet is become very much essential part of human life. Most of the attacks are happen at application layer which causes the security of applications. Such internet based applications includes banking, defense, education, medicine etc, which require high level security. This paper explains basic types of attacks which harmful for web applications like, cross Site Scripting attack, cross site request forgery, SQL Injection Attack, Server Misconfiguration and Predictable Page, Breaking Authentication Schemes, Logic Attacks, Web of Distrust. Now a day, most of the application development is based on XML. This paper described XML based application attack including Xpatth injection, Xquery injection and XSS injection in details. We also make survey of various traditional and recent approaches to detect, prevent and remove the web application attacks. We compare these applications based on technique used to detect attack, which type of attack they resolve, to check the approach which dataset they used and finally provide the limitation of that system and respective future directions. This will helpful for researchers for further research in respective field.
引用
收藏
页码:1174 / 1180
页数:7
相关论文
共 50 条
  • [21] Turning Web applications into Web Services by wrapping techniques
    Di Lorenzo, Giusy
    Fasolino, Anna Rita
    Melcarne, Lorenzo
    Tramontana, Porfirio
    Vittorini, Valenia
    14TH WORKING CONFERENCE ON REVERSE ENGINEERING, PROCEEDINGS, 2007, : 199 - 208
  • [22] Recent applications of web semantics in eLifeScience
    Clark, Tim
    Roos, Marco
    JOURNAL OF WEB SEMANTICS, 2014, 29 : 1 - 2
  • [23] Denial-of-service attack-detection techniques
    Carl, G
    Kesidis, G
    Brooks, RR
    Rai, S
    IEEE INTERNET COMPUTING, 2006, 10 (01) : 82 - 89
  • [24] Recent Advancements in Semantic Web Service Selection
    Pahariya, Riddhi
    Purohit, Lalit
    IETE JOURNAL OF RESEARCH, 2023, 69 (11) : 8090 - 8099
  • [25] Monitoring and recovery for web service applications
    Jocelyn Simmonds
    Shoham Ben-David
    Marsha Chechik
    Computing, 2013, 95 : 223 - 267
  • [26] Evolution and maintenance of web service applications
    Kajko-Mattsson, M
    20TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE, PROCEEDINGS, 2004, : 492 - 493
  • [27] Monitoring and recovery for web service applications
    Simmonds, Jocelyn
    Ben-David, Shoham
    Chechik, Marsha
    COMPUTING, 2013, 95 (03) : 223 - 267
  • [28] Automated schematization for web service applications
    Swan, Jerry
    Anand, Suchith
    Ware, Mark
    Jackson, Mike
    WEB AND WIRELESS GEOGRAPHICAL INFORMATION SYSTEMS, PROCEEDINGS, 2007, 4857 : 216 - +
  • [29] Monitoring and recovery of web service applications
    Simmonds J.
    Ben-David S.
    Chechik M.
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2010, 6400 : 250 - 288
  • [30] Performance Testing as a Service for Web Applications
    Ali, Amira
    Badr, Nagwa
    2015 IEEE SEVENTH INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTING AND INFORMATION SYSTEMS (ICICIS), 2015, : 356 - 361