Len Wirz, Asipan Ketphet, Nattapol Chiewnawintawat, Rinrada Tanthanathewin, S. Fugkeaw
{"title":"OWADIS: Rapid Discovery of OWASP10 Vulnerability based on Hybrid IDS","authors":"Len Wirz, Asipan Ketphet, Nattapol Chiewnawintawat, Rinrada Tanthanathewin, S. Fugkeaw","doi":"10.1109/KST57286.2023.10086878","DOIUrl":null,"url":null,"abstract":"Rapid advancements in internet applications introduce new vulnerabilities and threats that malicious actors are keen to exploit. These activities are becoming more versatile and challenging to address. In addition to implementing firewalls to control the inbound and outbound network traffic, an intrusion detection system (IDS) is commonly employed to monitor the network for malicious activities and policy violations. However, most IDSs are generally designed to monitor network traffic. They are incapable to detect the vulnerabilities embedded in the legitimate packets, especially the vulnerabilities targeting web applications. In this paper, we propose a cloud-based IDS with an emphasis on the detection of OWASP Top 10 Injection vulnerabilities, combined with additional common vulnerabilities such as brute-forcing and session hijacking. Furthermore, DDoS attacks, which are commonly seen, can also be detected with our proposed adaptable HTTP flooding detection engine. We also provide the evaluation to show that our proposed scheme provides fewer false positives than SNORT and gives efficient system throughput based on the leverage of Kafka and Spark streaming.","PeriodicalId":351833,"journal":{"name":"2023 15th International Conference on Knowledge and Smart Technology (KST)","volume":"16 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-02-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 15th International Conference on Knowledge and Smart Technology (KST)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/KST57286.2023.10086878","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Rapid advancements in internet applications introduce new vulnerabilities and threats that malicious actors are keen to exploit. These activities are becoming more versatile and challenging to address. In addition to implementing firewalls to control the inbound and outbound network traffic, an intrusion detection system (IDS) is commonly employed to monitor the network for malicious activities and policy violations. However, most IDSs are generally designed to monitor network traffic. They are incapable to detect the vulnerabilities embedded in the legitimate packets, especially the vulnerabilities targeting web applications. In this paper, we propose a cloud-based IDS with an emphasis on the detection of OWASP Top 10 Injection vulnerabilities, combined with additional common vulnerabilities such as brute-forcing and session hijacking. Furthermore, DDoS attacks, which are commonly seen, can also be detected with our proposed adaptable HTTP flooding detection engine. We also provide the evaluation to show that our proposed scheme provides fewer false positives than SNORT and gives efficient system throughput based on the leverage of Kafka and Spark streaming.