6
views
0
recommends
+1 Recommend
0 collections
    0
    shares
      • Record: found
      • Abstract: found
      • Article: found
      Is Open Access

      A closer look on Intrusion Detection System for web applications

      Preprint
      ,

      Read this article at

      Bookmark
          There is no author summary for this article yet. Authors can add summaries to their articles on ScienceOpen to make them more accessible to a non-specialist audience.

          Abstract

          Intrusion Detection System (IDS) is one of the security measures being used as an additional defence mechanism to prevent the security breaches on web. It has been well known methodology for detecting network-based attacks but still immature in the domain of securing web application. The objective of the paper is to thoroughly understand the design methodology of the detection system in respect to web applications. In this paper, we discuss several specific aspects of a web application in detail that makes challenging for a developer to build an efficient web IDS. The paper also provides a comprehensive overview of the existing detection systems exclusively designed to observe web traffic. Furthermore, we identify various dimensions for comparing the IDS from different perspectives based on their design and functionalities. We also provide a conceptual framework of an IDS with prevention mechanism to offer a systematic guidance for the implementation of the system specific to the web applications. We compare its features with five existing detection systems, namely AppSensor, PHPIDS, ModSecurity, Shadow Daemon and AQTRONIX WebKnight. The paper will highly facilitate the interest groups with the cutting edge information to understand the stronger and weaker sections of the web IDS and provide a firm foundation for developing an intelligent and efficient system.

          Related collections

          Most cited references7

          • Record: found
          • Abstract: not found
          • Article: not found

          A multi-model approach to the detection of web-based attacks

            Bookmark
            • Record: found
            • Abstract: not found
            • Article: not found

            Intrusion detection in web applications using text mining

              Bookmark
              • Record: found
              • Abstract: not found
              • Article: not found

              Using response action with intelligent intrusion detection and prevention system against web application malware

                Bookmark

                Author and article information

                Journal
                16 March 2018
                Article
                1803.06153
                3d28a694-1c09-4a20-a084-9d132bc5d3d9

                http://arxiv.org/licenses/nonexclusive-distrib/1.0/

                History
                Custom metadata
                cs.CR

                Comments

                Comment on this article