메뉴 건너뛰기




Volumn 17, Issue 3, 2009, Pages 305-329

Reducing errors in the anomaly-based detection of web-based attacks through the combined analysis of web requests and SQL queries

Author keywords

Anomaly detection; Data compartmentalization; Database security; Web security

Indexed keywords

ANOMALY DETECTION; ANOMALY DETECTION SYSTEMS; ANOMALY DETECTOR; BACK-END DATABASE; COMBINED ANALYSIS; COMMERCIAL PRODUCTS; CRITICAL INFORMATION; DATA COMPARTMENTALIZATION; DATABASE SECURITY; DETECTION RATES; EARLY WARNING; FALSE NEGATIVES; FALSE POSITIVE; FALSE POSITIVE RATES; RESEARCH PROTOTYPE; SENSITIVE INFORMATIONS; SQL QUERY; USAGE PATTERNS; WEB APPLICATION; WEB REQUESTS; WEB SECURITY; WEB SERVERS; WEB-BASED APPLICATIONS; WEB-BASED ATTACKS;

EID: 68149139611     PISSN: 0926227X     EISSN: None     Source Type: Journal    
DOI: 10.3233/JCS-2009-0321     Document Type: Article
Times cited : (29)

References (30)
  • 3
    • 84947584994 scopus 로고    scopus 로고
    • Application-integrated data collection for security monitoring
    • Proceedings of Recent Advances in Intrusion Detection RAID, Davis, CA, Springer
    • M. Almgren and U. Lindqvist, Application-integrated data collection for security monitoring, in: Proceedings of Recent Advances in Intrusion Detection (RAID), Davis, CA, LNCS, Vol. 2212, Springer, 2001, pp. 22-36.
    • (2001) LNCS , vol.2212 , pp. 22-36
    • Almgren, M.1    Lindqvist, U.2
  • 4
    • 68149138846 scopus 로고    scopus 로고
    • punBB, fast and lightweight PHP-powered discussion board
    • R. Andersson, punBB - fast and lightweight PHP-powered discussion board, 2005, http://www. punbb.org/
    • (2005)
    • Andersson, R.1
  • 12
    • 18844395404 scopus 로고    scopus 로고
    • A multi-model approach to the detection of web-based attacks
    • C. Kruegel, G. Vigna and W. Robertson, A multi-model approach to the detection of web-based attacks, Computer Networks 48(5) (2005), 717-738.
    • (2005) Computer Networks , vol.48 , Issue.5 , pp. 717-738
    • Kruegel, C.1    Vigna, G.2    Robertson, W.3
  • 14
    • 0036093229 scopus 로고    scopus 로고
    • Toward cost-sensitive modeling for intrusion detection and response
    • W. Lee, W. Fan, M. Miller, S. Stolfo and E. Zadok, Toward cost-sensitive modeling for intrusion detection and response, Journal of Computer Security 10(1) (2002), 5-12.
    • (2002) Journal of Computer Security , vol.10 , Issue.1 , pp. 5-12
    • Lee, W.1    Fan, W.2    Miller, M.3    Stolfo, S.4    Zadok, E.5
  • 16
    • 68149143610 scopus 로고    scopus 로고
    • myBloggie - PHP and mySQL Blog/Weblog script, 2005, http://mybloggie. mywebland.com/
    • myBloggie - PHP and mySQL Blog/Weblog script, 2005, http://mybloggie. mywebland.com/
  • 17
    • 68149135818 scopus 로고    scopus 로고
    • MySQL, The world's most popular open-source database
    • MySQL - The world's most popular open-source database, 2005, http://www.mysql.com/
    • (2005)
  • 18
    • 68149090760 scopus 로고    scopus 로고
    • NetContinuum, Nc-1100 af, August 2006, http://www.netcontinuum.com/
    • NetContinuum, Nc-1100 af, August 2006, http://www.netcontinuum.com/
  • 20
    • 68149084080 scopus 로고    scopus 로고
    • phPay, webshop or catalog based on SQL and PHP
    • phPay - webshop or catalog based on SQL and PHP, 2005, http://phpay.sourceforge.net/
    • (2005)
  • 22
    • 85090433665 scopus 로고    scopus 로고
    • Snort - lightweight intrusion detection for networks
    • Seattle, WA, November
    • M. Roesch, Snort - lightweight intrusion detection for networks, in: Proceedings of the USENIX LISA'99 Conference, Seattle, WA, November 1999.
    • (1999) Proceedings of the USENIX LISA'99 Conference
    • Roesch, M.1


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.