• DocumentCode
    1565640
  • Title

    Defending On-Line Web Application Security with User-Behavior Surveillance

  • Author

    Cheng, Yu-Chin ; Laih, Chi-Sung ; Lai, Gu-Hsin ; Chen, Chia-Mei ; Chen, Tsuhan

  • Author_Institution
    Nat. Cheng Kung Univ., Tainan
  • fYear
    2008
  • Firstpage
    410
  • Lastpage
    415
  • Abstract
    With the incoming of information era, web-based service has been developed rapidly and offered more and more business. These "open", and widely "web enabled" applications are subject to greater and greater levels and types of attacks as hackers exploit vulnerabilities within the software like SQL injection and cross site scripts (XSS) attack. In this paper, we proposed a type of novel embedded Markov model (EMM) to detect different web application attacks, monitor the on-line user behavior and defend the malevolent user promptly. Comparing to previous web application attacks detecting approaches, our EMM approach can not only detect user\´s invalidated input errors but also find out the unreasonable page transition behavior. By detecting unreasonable page transition, we can immediately defend the malevolent or silly user behavior to avoid the further web system failures and sensitive information disclosure. Furthermore, we implement an on-line user behavior surveillance system and use the real web traffic to evaluate the performance of our system. The experiment results show that our proposed EMM method can discover the abnormal behavior of malevolent user and detect the invalidated input attacks like SQL injection, XSS and string buffer overflow attacks.
  • Keywords
    Internet; Markov processes; SQL; security of data; telecommunication traffic; user interfaces; Cross Site Scripts attack; SQL injection; Web traffic; Web-based service; embedded Markov model; online Web application security; page transition behavior; string buffer overflow attacks; user-behavior surveillance; Application software; Availability; Buffer overflow; Computer crime; Computer hacking; Information security; Monitoring; National security; Statistics; Surveillance; Markov model; User behavior; Web application security; Web attacks; Web security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security, 2008. ARES 08. Third International Conference on
  • Conference_Location
    Barcelona
  • Print_ISBN
    978-0-7695-3102-1
  • Type

    conf

  • DOI
    10.1109/ARES.2008.127
  • Filename
    4529365