Browse > Article

Attack Categorization based on Web Application Analysis  

서정석 (한국과학기술원 전산학과)
김한성 (한국과학기술원 전산학과)
조상현 (한국과학기술원 전산학과)
차성덕 (한국과학기술원 전산학과)
Abstract
Frequency of attacks on web services and the resulting damage continue to grow as web services become popular. Techniques used in web service attacks are usually different from traditional network intrusion techniques, and techniques to protect web services are badly needed. Unfortunately, conventional intrusion detection systems (IDS), especially those based on known attack signatures, are inadequate in providing reasonable degree of security to web services. An application-level IDS, tailored to web services, is needed to overcome such limitations. The first step in developing web application IDS is to analyze known attacks on web services and characterize them so that anomaly-based intrusion defection becomes possible. In this paper, we classified known attack techniques to web services by analyzing causes, locations where such attack can be easily detected, and the potential risks.
Keywords
web attack; attack categorization; intrusion detection; network security; web application; information warfare; vulnerability analysis;
Citations & Related Records
연도 인용수 순위
  • Reference
1 M. Almgren, H. Debar, and M. Dacier, 'A Lightweight Tool for Detecting Web Server Attacks,' Proceedings of NDSS 2000, pp. 157-170, Feb. 2000
2 Short-The Open Source Network IDS, http://www.snort.org
3 Hobbes' Internet Timeline, http://www.zakon.org
4 Common Vulnerabilities and Exposures, http://cve.mitre.org
5 S. Pettit, 'Anatomy of a Web Application : Security Considerations,' Sanctum Inc. July, 2001
6 C. L. Liu, Elements of Discrete Mathematics 2nd Edition. pp.113, McGraw-Hill International Editions
7 Aleph One, 'Smashing The Stack For Fun And Profit,' BugTraq report, Nov. 1996
8 CERT/CC-Computer Emergency Response Team Coordination Center (Reproting Center for Internet Security Problem) http://www.cert.org
9 SecurityFocus, http://www.securityfocus.com
10 NTBugtraq, http://www.ntbugtraq.com