Title :
Detect HTTP Specification Attacks Using Ontology
Author :
Munir, Rana Faisal ; Ahmed, Nabeel ; Razzaq, Abdul ; Hur, Ali ; Ahmad, Farooq
Author_Institution :
Sch. of Electr. Eng. & Comput. Sci., Nat. Univ. of Sci. & Technol., Islamabad, Pakistan
Abstract :
Web applications after their revolutionary advent and popularity are target of variety of attacks. Magnitude and complexity of attacks is continuously growing with every minute development in World Wide Web. There are plenty of web attack detection techniques but they cannot fully comprehend the required degree of security for complex web applications. The reasons include static nature of attack detection mechanism, lack of expressiveness in attack detection rules, and absence of reasoning capability to detect unanticipated ways an attack can be launched. To cater these issues, a formal approach is required that has more expressiveness and equipped with reasoning. These traits are fully adhered to by the Semantic techniques. This paper introduces an approach for utilizing Semantic techniques in web application security. This has never been introduced previously to the best of our knowledge. Here the HTTP Protocol ontology is presented to mitigate the communication protocol attacks. In this paper we are focusing on communication protocol attacks including abnormal HTTP messages, HTTP request smuggling and HTTP response splitting. While dealing with these attacks, the proposed technique outperforms the existing solutions with higher detection rate and low false positives as indicated by evaluation results.
Keywords :
Internet; hypermedia; inference mechanisms; ontologies (artificial intelligence); protocols; security of data; HTTP messages; HTTP protocol ontology; HTTP request smuggling; HTTP response splitting; HTTP specification attack detection; Web application security; Web attack detection techniques; World Wide Web; attack detection mechanism static nature; attack detection rules; communication protocol attacks; expressiveness lackness; formal approach; reasoning capability absence; Information security; Internet; Microstrip; Ontologies; Protocols; Semantics; Ontology Engineering; Protocol Validation; Request Smuggling; Response Splitting; Web Application Attacks;
Conference_Titel :
Frontiers of Information Technology (FIT), 2011
Conference_Location :
Islamabad
Print_ISBN :
978-1-4673-0209-8
DOI :
10.1109/FIT.2011.21