• DocumentCode
    3122261
  • Title

    Detect HTTP Specification Attacks Using Ontology

  • Author

    Munir, Rana Faisal ; Ahmed, Nabeel ; Razzaq, Abdul ; Hur, Ali ; Ahmad, Farooq

  • Author_Institution
    Sch. of Electr. Eng. & Comput. Sci., Nat. Univ. of Sci. & Technol., Islamabad, Pakistan
  • fYear
    2011
  • fDate
    19-21 Dec. 2011
  • Firstpage
    75
  • Lastpage
    78
  • Abstract
    Web applications after their revolutionary advent and popularity are target of variety of attacks. Magnitude and complexity of attacks is continuously growing with every minute development in World Wide Web. There are plenty of web attack detection techniques but they cannot fully comprehend the required degree of security for complex web applications. The reasons include static nature of attack detection mechanism, lack of expressiveness in attack detection rules, and absence of reasoning capability to detect unanticipated ways an attack can be launched. To cater these issues, a formal approach is required that has more expressiveness and equipped with reasoning. These traits are fully adhered to by the Semantic techniques. This paper introduces an approach for utilizing Semantic techniques in web application security. This has never been introduced previously to the best of our knowledge. Here the HTTP Protocol ontology is presented to mitigate the communication protocol attacks. In this paper we are focusing on communication protocol attacks including abnormal HTTP messages, HTTP request smuggling and HTTP response splitting. While dealing with these attacks, the proposed technique outperforms the existing solutions with higher detection rate and low false positives as indicated by evaluation results.
  • Keywords
    Internet; hypermedia; inference mechanisms; ontologies (artificial intelligence); protocols; security of data; HTTP messages; HTTP protocol ontology; HTTP request smuggling; HTTP response splitting; HTTP specification attack detection; Web application security; Web attack detection techniques; World Wide Web; attack detection mechanism static nature; attack detection rules; communication protocol attacks; expressiveness lackness; formal approach; reasoning capability absence; Information security; Internet; Microstrip; Ontologies; Protocols; Semantics; Ontology Engineering; Protocol Validation; Request Smuggling; Response Splitting; Web Application Attacks;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Frontiers of Information Technology (FIT), 2011
  • Conference_Location
    Islamabad
  • Print_ISBN
    978-1-4673-0209-8
  • Type

    conf

  • DOI
    10.1109/FIT.2011.21
  • Filename
    6137122