DoubleGuard: Detecting Intrusions in Multitier Web Applications

Cited 13 time in webofscience Cited 34 time in scopus
  • Hit : 989
  • Download : 0
DC FieldValueLanguage
dc.contributor.authorLe, Meixingko
dc.contributor.authorStavrou, Angelosko
dc.contributor.authorKang, Brent ByungHoonko
dc.date.accessioned2013-08-29T02:30:45Z-
dc.date.available2013-08-29T02:30:45Z-
dc.date.created2013-08-21-
dc.date.created2013-08-21-
dc.date.created2013-08-21-
dc.date.created2013-08-21-
dc.date.issued2012-07-
dc.identifier.citationIEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, v.9, no.4, pp.512 - 525-
dc.identifier.issn1545-5971-
dc.identifier.urihttp://hdl.handle.net/10203/176618-
dc.description.abstractInternet services and applications have become an inextricable part of daily life, enabling communication and the management of personal information from anywhere. To accommodate this increase in application and data complexity, web services have moved to a multitiered design wherein the webserver runs the application front-end logic and data are outsourced to a database or file server. In this paper, we present DoubleGuard, an IDS system that models the network behavior of user sessions across both the front-end webserver and the back-end database. By monitoring both web and subsequent database requests, we are able to ferret out attacks that an independent IDS would not be able to identify. Furthermore, we quantify the limitations of any multitier IDS in terms of training sessions and functionality coverage. We implemented DoubleGuard using an Apache webserver with MySQL and lightweight virtualization. We then collected and processed real-world traffic over a 15-day period of system deployment in both dynamic and static web applications. Finally, using DoubleGuard, we were able to expose a wide range of attacks with 100 percent accuracy while maintaining 0 percent false positives for static web services and 0.6 percent false positives for dynamic web services.-
dc.languageEnglish-
dc.publisherIEEE COMPUTER SOC-
dc.titleDoubleGuard: Detecting Intrusions in Multitier Web Applications-
dc.typeArticle-
dc.identifier.wosid000304147900007-
dc.identifier.scopusid2-s2.0-84861175145-
dc.type.rimsART-
dc.citation.volume9-
dc.citation.issue4-
dc.citation.beginningpage512-
dc.citation.endingpage525-
dc.citation.publicationnameIEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING-
dc.identifier.doi10.1109/TDSC.2011.59-
dc.contributor.localauthorKang, Brent ByungHoon-
dc.contributor.nonIdAuthorLe, Meixing-
dc.contributor.nonIdAuthorStavrou, Angelos-
dc.description.isOpenAccessN-
dc.type.journalArticleArticle-
dc.subject.keywordAuthorAnomaly detection-
dc.subject.keywordAuthorvirtualization-
dc.subject.keywordAuthormultitier web application-
dc.subject.keywordPlusDETECTION SYSTEMS-
Appears in Collection
CS-Journal Papers(저널논문)
Files in This Item
There are no files associated with this item.
This item is cited by other documents in WoS
⊙ Detail Information in WoSⓡ Click to see webofscience_button
⊙ Cited 13 items in WoS Click to see citing articles in records_button

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0