A stateful intrusion detection system for world-wide web servers

被引:45
|
作者
Vigna, G [1 ]
Robertson, W [1 ]
Kher, V [1 ]
Kemmerer, RA [1 ]
机构
[1] Univ Calif Santa Barbara, Dept Comp Sci, Reliable Software Grp, Santa Barbara, CA 93106 USA
关键词
world-wide web; security; intrusion detection;
D O I
10.1109/CSAC.2003.1254308
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Web servers are ubiquitous, remotely accessible, and often misconfigured. In addition, custom web-based applications may introduce vulnerabilities that are overlooked even by the most security-conscious server administrators. Consequently, web servers are a popular target for hackers. To mitigate the security exposure associated with web servers, intrusion detection systems are deployed to analyze and screen incoming requests. The goal is to perform early detection of malicious activity and possibly prevent more serious damage to the protected site. Even though intrusion detection is critical for the security of web servers, the intrusion detection systems available today only perform very simple analyses and are often vulnerable to simple evasion techniques. In addition, most systems do not provide sophisticated attack languages that allow a system administrator to specify custom, complex attack scenarios to be detected. This paper presents WebSTAT an intrusion detection system that analyzes web requests looking for evidence of malicious behavior The system is novel in several ways. First of all, it provides a sophisticated language to describe multi-step attacks in terms of states and transitions. In addition, the modular nature of the system supports the integrated analysis of network traffic sent to the server host, operating system-level audit data produced by the server host, and the access logs produced by, the web server BY correlating different streams of events, it is possible to achieve more effective detection of web-based attacks.
引用
收藏
页码:34 / 43
页数:10
相关论文
共 50 条
  • [1] Weighted fair queueing scheduling for world-wide web proxy servers
    Khayari, RE
    Sadre, R
    Haverkort, B
    Zoschke, N
    INTERNET PERFORMANCE AND CONTROL OF NETWORK SYSTEMS III, 2002, 4865 : 120 - 131
  • [2] A world-wide web server on a multicomputer system
    Wu, CH
    Yeh, CC
    Juang, JY
    SECOND INTERNATIONAL SYMPOSIUM ON PARALLEL ARCHITECTURES, ALGORITHMS, AND NETWORKS (I-SPAN '96), PROCEEDINGS, 1996, : 522 - 528
  • [3] The world-wide waste web
    Johann H. Martínez
    Sergi Romero
    José J. Ramasco
    Ernesto Estrada
    Nature Communications, 13
  • [4] Introducing the World-Wide Web
    Downes, PK
    BRITISH DENTAL JOURNAL, 1998, 185 (07) : 328 - 332
  • [5] The world-wide wireless web
    Abdi, B
    Maass, E
    2002 IEEE RADIO FREQUENCY INTEGRATED CIRCUITS (RFIC) SYMPOSIUM, DIGEST OF PAPERS, 2002, : 3 - 6
  • [6] The world-wide waste web
    Martinez, Johann H.
    Romero, Sergi
    Ramasco, Jose J.
    Estrada, Ernesto
    NATURE COMMUNICATIONS, 2022, 13 (01)
  • [7] Introducing the World-Wide Web
    P K Downes
    British Dental Journal, 1998, 185 : 328 - 332
  • [8] Diameter of the World-Wide Web
    Réka Albert
    Hawoong Jeong
    Albert-László Barabási
    Nature, 1999, 401 : 130 - 131
  • [9] The Need for an Internally Developed Intrusion Detection System for Web Servers
    Marymount University
  • [10] Intrusion detection system for securing Geographical Information System web servers
    Park, JS
    Jin, HT
    Kim, DS
    WEB AND WIRELESS GEOGRAPHICAL INFORMATION SYSTEMS, 2005, 3428 : 110 - 119