DocumentCode
1376245
Title
DoubleGuard: Detecting Intrusions in Multitier Web Applications
Author
Le, Meixing ; Stavrou, Angelos ; Kang, Brent ByungHoon
Author_Institution
Dept. of Comput. Sci., George Mason Univ., Fairfax, VA, USA
Volume
9
Issue
4
fYear
2012
Firstpage
512
Lastpage
525
Abstract
Internet services and applications have become an inextricable part of daily life, enabling communication and the management of personal information from anywhere. To accommodate this increase in application and data complexity, web services have moved to a multitiered design wherein the webserver runs the application front-end logic and data are outsourced to a database or file server. In this paper, we present DoubleGuard, an IDS system that models the network behavior of user sessions across both the front-end webserver and the back-end database. By monitoring both web and subsequent database requests, we are able to ferret out attacks that an independent IDS would not be able to identify. Furthermore, we quantify the limitations of any multitier IDS in terms of training sessions and functionality coverage. We implemented DoubleGuard using an Apache webserver with MySQL and lightweight virtualization. We then collected and processed real-world traffic over a 15-day period of system deployment in both dynamic and static web applications. Finally, using DoubleGuard, we were able to expose a wide range of attacks with 100 percent accuracy while maintaining 0 percent false positives for static web services and 0.6 percent false positives for dynamic web services.
Keywords
SQL; Web services; database management systems; security of data; virtualisation; Apache Web server; DoubleGuard; IDS system; Internet services; MySQL; Web services; application front-end logic; back-end database; data complexity; database requests; front-end Web server; intrusion detection; multitier Web applications; multitiered design; network behavior; personal information management; Containers; Databases; Service oriented architecture; Training; Web servers; Anomaly detection; multitier web application.; virtualization;
fLanguage
English
Journal_Title
Dependable and Secure Computing, IEEE Transactions on
Publisher
ieee
ISSN
1545-5971
Type
jour
DOI
10.1109/TDSC.2011.59
Filename
6081881
Link To Document