Web应用防火墙规避技术

K. Nagendran, S. Balaji, B. A. Raj, P. Chanthrika, RG Amirthaa
{"title":"Web应用防火墙规避技术","authors":"K. Nagendran, S. Balaji, B. A. Raj, P. Chanthrika, RG Amirthaa","doi":"10.1109/ICACCS48705.2020.9074217","DOIUrl":null,"url":null,"abstract":"Recently there has been a robust increase in cyber attacks. Statistical studies show that around 4% of internet traffic is malicious. Firewalls are deployed as blocking mechanisms to identify and prevent malicious requests. They filter seemingly malicious packets based on the filter rules. Despite the filters, there are certain evasion techniques used by attackers to bypass the firewall. This paper describes the techniques for bypassing the web application firewall based on their configurations and paranoia levels of implementation so that security researchers can understand loop holes in the firewall to build a better firewall strategy. By these techniques, an attacker can achieve the attacks he intends to do even if the firewall is placed between the web application and the client.","PeriodicalId":439003,"journal":{"name":"2020 6th International Conference on Advanced Computing and Communication Systems (ICACCS)","volume":"9 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-03-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"Web Application Firewall Evasion Techniques\",\"authors\":\"K. Nagendran, S. Balaji, B. A. Raj, P. Chanthrika, RG Amirthaa\",\"doi\":\"10.1109/ICACCS48705.2020.9074217\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Recently there has been a robust increase in cyber attacks. Statistical studies show that around 4% of internet traffic is malicious. Firewalls are deployed as blocking mechanisms to identify and prevent malicious requests. They filter seemingly malicious packets based on the filter rules. Despite the filters, there are certain evasion techniques used by attackers to bypass the firewall. This paper describes the techniques for bypassing the web application firewall based on their configurations and paranoia levels of implementation so that security researchers can understand loop holes in the firewall to build a better firewall strategy. By these techniques, an attacker can achieve the attacks he intends to do even if the firewall is placed between the web application and the client.\",\"PeriodicalId\":439003,\"journal\":{\"name\":\"2020 6th International Conference on Advanced Computing and Communication Systems (ICACCS)\",\"volume\":\"9 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-03-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2020 6th International Conference on Advanced Computing and Communication Systems (ICACCS)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICACCS48705.2020.9074217\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 6th International Conference on Advanced Computing and Communication Systems (ICACCS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICACCS48705.2020.9074217","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

最近,网络攻击急剧增加。统计研究表明,大约4%的互联网流量是恶意的。防火墙被部署为阻塞机制,以识别和防止恶意请求。它们根据过滤规则过滤看似恶意的数据包。尽管有过滤器,攻击者还是使用了某些规避技术来绕过防火墙。本文根据web应用程序防火墙的配置和实现的偏执程度描述了绕过它们的技术,以便安全研究人员能够了解防火墙中的循环漏洞,从而构建更好的防火墙策略。通过这些技术,即使在web应用程序和客户端之间放置了防火墙,攻击者也可以实现他想要进行的攻击。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Web Application Firewall Evasion Techniques
Recently there has been a robust increase in cyber attacks. Statistical studies show that around 4% of internet traffic is malicious. Firewalls are deployed as blocking mechanisms to identify and prevent malicious requests. They filter seemingly malicious packets based on the filter rules. Despite the filters, there are certain evasion techniques used by attackers to bypass the firewall. This paper describes the techniques for bypassing the web application firewall based on their configurations and paranoia levels of implementation so that security researchers can understand loop holes in the firewall to build a better firewall strategy. By these techniques, an attacker can achieve the attacks he intends to do even if the firewall is placed between the web application and the client.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信