Formal reasoning of web application Firewall rules through ontological modeling

Ali Ahmad, Z. Anwar, Ali Hur, H. F. Ahmad
{"title":"Formal reasoning of web application Firewall rules through ontological modeling","authors":"Ali Ahmad, Z. Anwar, Ali Hur, H. F. Ahmad","doi":"10.1109/INMIC.2012.6511505","DOIUrl":null,"url":null,"abstract":"Web application Firewalls (WAF)s are security tools that protect web application from external attacks. They do so by applying a set of security policy rules on HTTP traffic generated and received by web applications. These policies Rules are in-fact the heart of WAFs which are unable to provide strong protection on their own without well-written policy rules. Unfortunately due to complexity of web application and increased sophistication of application level attacks the rule configuration and management for WAFs is an error prone and tedious task. This paper is an effort to explore the effectiveness of an Ontology based framework for modeling, configuring, querying and reasoning overWAF Firewall configurations.We have tested our framework on a leading open source web application firewalls known as ModSecurity. Our preliminary results show that our framework significantly improves configuration errors in the WAF ruleset that arise because of duplication and policy conflicts.","PeriodicalId":396084,"journal":{"name":"2012 15th International Multitopic Conference (INMIC)","volume":"84 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2012-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"8","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2012 15th International Multitopic Conference (INMIC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/INMIC.2012.6511505","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 8

Abstract

Web application Firewalls (WAF)s are security tools that protect web application from external attacks. They do so by applying a set of security policy rules on HTTP traffic generated and received by web applications. These policies Rules are in-fact the heart of WAFs which are unable to provide strong protection on their own without well-written policy rules. Unfortunately due to complexity of web application and increased sophistication of application level attacks the rule configuration and management for WAFs is an error prone and tedious task. This paper is an effort to explore the effectiveness of an Ontology based framework for modeling, configuring, querying and reasoning overWAF Firewall configurations.We have tested our framework on a leading open source web application firewalls known as ModSecurity. Our preliminary results show that our framework significantly improves configuration errors in the WAF ruleset that arise because of duplication and policy conflicts.
通过本体建模对web应用防火墙规则进行形式化推理
Web应用防火墙(WAF)是保护Web应用不受外部攻击的安全工具。他们通过对web应用程序生成和接收的HTTP流量应用一组安全策略规则来实现这一点。这些政策规则实际上是waf的核心,如果没有良好的政策规则,waf本身就无法提供强大的保护。不幸的是,由于web应用程序的复杂性和应用程序级攻击的复杂性增加,waf的规则配置和管理是一项容易出错且乏味的任务。本文旨在探索基于本体的框架对waf防火墙配置进行建模、配置、查询和推理的有效性。我们已经在领先的开源web应用防火墙ModSecurity上测试了我们的框架。我们的初步结果表明,我们的框架显著改善了由于重复和策略冲突而出现的WAF规则集中的配置错误。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信