DocumentCode
1640069
Title
Detecting web application attacks with use of Gene Expression Programming
Author
Skaruz, Jaroslaw ; Seredynski, Franciszek
Author_Institution
Inst. of Comput. Sci., Univ. of Podlasie, Siedlce
fYear
2009
Firstpage
2029
Lastpage
2035
Abstract
In the paper we present a novel approach based on applying a modern metaheuristic Gene Expression Programming (GEP) to detecting web application attacks. This class of attacks relates to malicious activity of an intruder against applications, which use a database for storing data. The application uses SQL to retrieve data from the database and web server mechanisms to put them in a web browser. A poor implementation allows an attacker to modify SQL statements originally developed by a programmer, which leads to stealing or modifying data to which the attacker has not privileges. While the attack consists in modification of SQL queries sent to the database, they are the only one source of information used for detecting attacks. Intrusion detection problem is transformed into classification problem, which the objective is to classify SQL queries between either normal or malicious queries. GEP is used to find a function used for classification of SQL queries. Experimental results are presented on the basis of SQL queries of different length. The findings show that the efficiency of detecting SQL statements representing attacks depends on the length of SQL statements. Additionally we studied the impact of classification threshold on the obtained results.
Keywords
SQL; genetic algorithms; online front-ends; query processing; security of data; SQL; Web application attack detection; Web browser; Web server mechanisms; data retrieval; intrusion detection problem; metaheuristic gene expression programming; Application software; Computer science; Data security; Databases; Gene expression; Information retrieval; Information technology; Intrusion detection; Phase detection; Web server;
fLanguage
English
Publisher
ieee
Conference_Titel
Evolutionary Computation, 2009. CEC '09. IEEE Congress on
Conference_Location
Trondheim
Print_ISBN
978-1-4244-2958-5
Electronic_ISBN
978-1-4244-2959-2
Type
conf
DOI
10.1109/CEC.2009.4983190
Filename
4983190
Link To Document