DocumentCode :
3077672
Title :
A Comprehensive Client-Side Behavior Model for Diagnosing Attacks in Ajax Applications
Author :
Xinshu Dong ; Patil, K. ; Jian Mao ; Zhenkai Liang
Author_Institution :
Sch. of Comput., Nat. Univ. of Singapore, Singapore, Singapore
fYear :
2013
fDate :
17-19 July 2013
Firstpage :
177
Lastpage :
187
Abstract :
Behavior models of applications are widely used for diagnosing security incidents in complex web-based systems. However, Ajax techniques that enable better web experiences also make it fairly challenging to model Ajax application behaviors in the complex browser environment. In Ajax applications, server-side states are no longer synchronous with the views to end users at the client side. Therefore, to model the behaviors of Ajax applications, it is indispensable to incorporate client-side application states into the behavior models, as being explored by prior work. Unfortunately, how to leverage behavior models to perform security diagnosis in Ajax applications has yet been thoroughly examined. Existing models extracted from Ajax application behaviors are insufficient in a security context. In this paper, we propose a new behavior model for diagnosing attacks in Ajax applications, which abstracts both client-side state transitions as well as their communications to external servers. Our model articulates different states with the browser events or user actions that trigger state transitions. With a prototype implementation, we demonstrate that the proposed model is effective in attack diagnosis for real-world Ajax applications.
Keywords :
Internet; online front-ends; security of data; attack diagnosis; browser events; complex Web-based systems; complex browser environment; comprehensive client-side behavior model; external servers; prototype implementation; real-world Ajax applications; security incident diagnosis; state transitions; user actions; Browsers; Context; Electronic mail; Load modeling; Security; Web servers;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Engineering of Complex Computer Systems (ICECCS), 2013 18th International Conference on
Conference_Location :
Singapore
Print_ISBN :
978-0-7695-5007-7
Type :
conf
DOI :
10.1109/ICECCS.2013.35
Filename :
6601822
Link To Document :
بازگشت