NUST Institutional Repository

Detection Of Probing Attacks In SWAF

Show simple item record

dc.contributor.author Hamid, Sundas
dc.date.accessioned 2020-11-05T09:49:24Z
dc.date.available 2020-11-05T09:49:24Z
dc.date.issued 2011
dc.identifier.uri http://10.250.8.41:8080/xmlui/handle/123456789/10237
dc.description Supervisor: Dr. Hafiz Farooq Ahmad en_US
dc.description.abstract Probing is the major issue in web application security but there does not exit reasonable progress to detect probing before the actual attack is launched. The key challenge is to identify attacker’s probing process for gathering information of vulnerabilities in Web application and take appropriate actions quickly before attackers exploit them. In this research work, we propose a methodology to detect probing; it is currently implemented as a part of SWAF (Semantic Based Web Applications Firewall) project. It assists SWAF to detect probing before an attacker is able to exploit vulnerabilities. Most of the vulnerabilities are discovered as a result of trial and error by the attacker. We make it possible to detect probing by using three techniques viz. XML rules, SWAF log and application profiling (together comes under threshold learning) and carrying out behavioral analysis of the attackers traffic to detect and block them. The proposed methodology increases the detection rate of SWAF and considerably decreases the attack ratio. As a part of this work we have also evaluated the performance of SWAF with probing detection technique using most popular scanners. Evaluation results confirm the effectiveness of proposed approach as it detects scanners with high detection rate. en_US
dc.publisher SEECS, National University of Science and Technology, Islamabad. en_US
dc.subject Information Technology, en_US
dc.subject Probing Attacks en_US
dc.title Detection Of Probing Attacks In SWAF en_US
dc.type Thesis en_US


Files in this item

This item appears in the following Collection(s)

  • MS [432]

Show simple item record

Search DSpace


Advanced Search

Browse

My Account