期刊论文详细信息
Advances in Electrical and Computer Engineering
An Enhanced Rule-Based Web Scanner Based on Similarity Score
LEE, M1 
关键词: intrusion detection;    access control;    information security;    web services;    security;   
DOI  :  10.4316/AECE.2016.03002
学科分类:计算机科学(综合)
来源: Universitatea "Stefan cel Mare" din Suceava
PDF
【 摘 要 】
This paper proposes an enhanced rule-based web scanner in order to get better accuracy in detecting web vulnerabilities than the existing tools, which have relatively high false alarm rate when the web pages are installed in unconventional directory paths. Using the proposed matching method based on similarity score, the proposed scheme can determine whether two pages have the same vulnerabilities or not. With this method, the proposed scheme is able to figure out the target web pages are vulnerable by comparing them to the web pages that are known to have vulnerabilities. We show the proposed scanner reduces 12% false alarm rate compared to the existing well-known scanner through the performance evaluation via various experiments. The proposed scheme is especially helpful in detecting vulnerabilities of the web applications which come from well-known open-source web applications after small customization, which happens frequently in many small-sized companies.
【 授权许可】

Unknown   

【 预 览 】
附件列表
Files Size Format View
RO201904035520940ZK.pdf 1212KB PDF download
  文献评价指标  
  下载次数:16次 浏览次数:49次