The Experts below are selected from a list of 3300 Experts worldwide ranked by ideXlab platform

Brasil. Superior Tribunal De Justiça - One of the best experts on this subject based on the ideXlab platform.

  • Portaria STJ/SAD n. 24 de 15 de janeiro de 2019
    2019
    Co-Authors: Brasil. Superior Tribunal De Justiça
    Abstract:

    Designa a Comissão de Recebimento provisório e definitivo referente ao Contrato STJ n. 87/2018, que tem por objeto o fornecimento de solução de Web Application Firewall (WAF) com serviços de instalação, configuração, suporte técnico e treinamento

  • Portaria STJ/SAD n. 23 de 15 de janeiro de 2019
    2019
    Co-Authors: Brasil. Superior Tribunal De Justiça
    Abstract:

    Designa o titular da Seção de Segurança de Rede e o seu substituto, respectivamente, como gestor e gestor substituto do Contrato STJ n. 87/2018, firmado com a empresa Teltec Solutions Ltda., que tem por objeto o fornecimento de solução de Web Application Firewall (WAF) com serviços de instalação, configuração, suporte técnico e treinamento

Hafiz Farooq Ahmad - One of the best experts on this subject based on the ideXlab platform.

  • formal reasoning of web Application Firewall rules through ontological modeling
    2012 15th International Multitopic Conference (INMIC), 2012
    Co-Authors: Ali Ahmad, Ali Hur, Zahid Anwar, Hafiz Farooq Ahmad
    Abstract:

    Web Application Firewalls (WAF)s are security tools that protect web Application from external attacks. They do so by applying a set of security policy rules on HTTP traffic generated and received by web Applications. These policies Rules are in-fact the heart of WAFs which are unable to provide strong protection on their own without well-written policy rules. Unfortunately due to complexity of web Application and increased sophistication of Application level attacks the rule configuration and management for WAFs is an error prone and tedious task. This paper is an effort to explore the effectiveness of an Ontology based framework for modeling, configuring, querying and reasoning overWAF Firewall configurations.We have tested our framework on a leading open source web Application Firewalls known as ModSecurity. Our preliminary results show that our framework significantly improves configuration errors in the WAF ruleset that arise because of duplication and policy conflicts.

  • Application for autonomous decentralized multi layer cache system to web Application Firewall
    International Symposium on Autonomous Decentralized Systems, 2011
    Co-Authors: Hironao Takahashi, Hafiz Farooq Ahmad, Kinji Mori
    Abstract:

    Web service demand is heterogeneous and it is expanding day by day. Malicious web attacks particularly at Application layer, are also increasing significantly. It is estimated eighty percent (80%) malicious attacks are web Application layer attacks such as Cross Site Scripting and SQL injection. Such attacks have affected financial organizations, government institutes, hospitals and enterprise companies and so on. It is required to detect such attacks instantly to maintain the safe operations. Existing Web Application Firewalls (WAF) aim at protection of web Application attacks using Black and White list based approach. Black list based WAFs operate at security operation center (SOC) to protect known attacks and it is easy to maintain same black list by other WAF nodes. However, white list independent signature from each Web service and it is generated by each web site policy. When the event of WAF fails, other WAF doesn't have same level of White list at that time. Black list is common type of signature and it can be keep the assurance by multiple WAF nodes or proxy node but White list is individual type of signature and can't maintain assurance by same policy of node. Therefore, to maintain high detection rate, dynamic adaptability of White list is required. It also requires online property and timeliness response. To solve these issues, an integrated Autonomous Decentralized Multi Layer Cache (ADMLC) system with Web Application Firewall is proposed. Evaluation shows that proposed architecture detection rate is much better than other traditional WAF based systems.

  • autonomous short latency system for web Application layer Firewall
    World Congress on Services, 2010
    Co-Authors: Hironao Takahashi, Kinji Mori, Hafiz Farooq Ahmad
    Abstract:

    Real time Application was required many types of industrial controllers, factory machines since 20-century. It is also utilizing many types of real time controllers for vehicle such as train, automobile and so on [1]. On the other hand, Web services that are using Internet are required short latency system. When the accesses are increased, services of quality are so important factors to achieve their requirement. Thus, these web services are facing different levels of requirement. One is short latency of time service and other one is protection from malicious access. To support two of both at same time, it is big challenge in Web service today. The main issue is malicious web attacks on web Application layer level accesses that came up recently. Today's web service provider is attempting to achieve this level of service. There are a few Web Application level security technology but the all of their approach is black list or white list base. To analyze these HTTP protocol accesses, web site is always required high performance list search and compares them. From the analyzing processes have some events overhead. Keeping short latency of time, it needs high I/O performance solution. This paper is proposing L3 block cache node with eventually consistency technology to achieve timeliness autonomous decentralized system. The latency of time is compared with traditional approach system. Jmeter based web access response evaluation is shown very positive result. Thus, proposing short latency node system is great solution for Web Application Firewall with short latency.

Roli Fabio - One of the best experts on this subject based on the ideXlab platform.

  • DeltaPhish: Detecting phishing webpages in compromised websites
    'Springer Science and Business Media LLC', 2017
    Co-Authors: Corona Igino, Biggio Battista, Contini Matteo, Piras Luca, Corda Roberto, Mereu Mauro, Mureddu Guido, Ariu Davide, Roli Fabio
    Abstract:

    The large-scale deployment of modern phishing attacks relies on the automatic exploitation of vulnerable websites in the wild, to maximize profit while hindering attack traceability, detection and blacklisting. To the best of our knowledge, this is the first work that specifically leverages this adversarial behavior for detection purposes. We show that phishing webpages can be accurately detected by highlighting HTML code and visual differences with respect to other (legitimate) pages hosted within a compromised website. Our system, named DeltaPhish, can be installed as part of a web Application Firewall, to detect the presence of anomalous content on a website after compromise, and eventually prevent access to it. DeltaPhish is also robust against adversarial attempts in which the HTML code of the phishing page is carefully manipulated to evade detection. We empirically evaluate it on more than 5,500 webpages collected in the wild from compromised websites, showing that it is capable of detecting more than 99% of phishing webpages, while only misclassifying less than 1% of legitimate pages. We further show that the detection rate remains higher than 70% even under very sophisticated attacks carefully designed to evade our system

  • DeltaPhish: Detecting Phishing Webpages in Compromised Websites
    2017
    Co-Authors: Corona Igino, Biggio Battista, Contini Matteo, Piras Luca, Corda Roberto, Mereu Mauro, Mureddu Guido, Ariu Davide, Roli Fabio
    Abstract:

    The large-scale deployment of modern phishing attacks relies on the automatic exploitation of vulnerable websites in the wild, to maximize profit while hindering attack traceability, detection and blacklisting. To the best of our knowledge, this is the first work that specifically leverages this adversarial behavior for detection purposes. We show that phishing webpages can be accurately detected by highlighting HTML code and visual differences with respect to other (legitimate) pages hosted within a compromised website. Our system, named DeltaPhish, can be installed as part of a web Application Firewall, to detect the presence of anomalous content on a website after compromise, and eventually prevent access to it. DeltaPhish is also robust against adversarial attempts in which the HTML code of the phishing page is carefully manipulated to evade detection. We empirically evaluate it on more than 5,500 webpages collected in the wild from compromised websites, showing that it is capable of detecting more than 99% of phishing webpages, while only misclassifying less than 1% of legitimate pages. We further show that the detection rate remains higher than 70% even under very sophisticated attacks carefully designed to evade our system.Comment: Preprint version of the work accepted at ESORICS 201

Yao Linlina - One of the best experts on this subject based on the ideXlab platform.

  • web Application Firewall based on distributed p2p architecture
    Computer Engineering, 2012
    Co-Authors: Yao Linlina
    Abstract:

    In order to make up the insignificance of Web Application Firewall(WAF) with single node in detection efficiency and stability,a WAF based on distributed and P2P architecture is designed and implemented by using reverse proxy technology.Reverse proxy technology is used to response the Web request.Aiming to implementing P2P architecture,the same program is run on each node.Master and auxiliary nodes are determined dynamically by demands.The master node has the characteristics of session keeping and load balance,and auxiliary nodes detect messages by expert library and plug-in components.Experimental results show that the system can effectively prevent attacks from Application layer,and it is more efficient and stable than single node.

Jeichande, Dauto Ussene - One of the best experts on this subject based on the ideXlab platform.

  • Redundant Firewalls for web Applications
    2016
    Co-Authors: Jeichande, Dauto Ussene
    Abstract:

    Tese de mestrado, Segurança Informática, Universidade de Lisboa, Faculdade de Ciências, 2016The websites of small, medium and large companies are a great competitive advantage in the business world. Companies invest a considerable amount of money to ensure they appear on top of the ranks when users seek for goods and services in search engines. On the other hand, websites open yet another door for an adversary to compromise the security of the organizations. The conventional network Firewalls and intrusion prevention systems have limitations in protecting web Applications because they operate at the network layer. The Web Application Firewall (WAF) is a solution that companies use to mitigate these limitations. The difference is in the ability to analyze the logic of the Application layer. The WAF not only detects known attacks on the web Application environment but can also detect and prevent new types of attacks through pattern analysis to traffic. This project aims to implement a redundant WAF architecture using the concept of diversity at the operating system (OS), web server and WAF technology. To evaluate the solution proposed we used vulnerabilities scanner tools to execute a set of security tests and a web load tests tool to measure the response times. The evaluation compared the resilience and impact on the performance of our architecture with several other configurations, with and without WAFs.Nos dias de hoje, as páginas de Internet das pequenas, médias e grandes empresas são uma grande vantagem competitiva no Mundo de negócios. As empresas investem consideravelmente para garantir que aparecem em primeiro lugar quando os utilizadores pesquisam por bens e serviços nos motares de busca. Por outro lado, os adversários usam este tipo de acesso para tentar comprometer a segurança das organizações. Os filtros de rede convencionais e detetores de intrusões apresentam limitações na proteção das aplicações web porque eles inspecionam ao nível da camada de rede. Os filtros para aplicações web (WAF) são uma solução que as empresas usam para mitigar estas limitações. A diferença está na habilidade de analisar a lógica da camada aplicacional. As WAFs não detetam somente ataques conhecidos no ambiente aplicacional web como também e quando devidamente configuradas podem detetar e prevenir novos tipos de ataques através da análise de padrões do tráfego. Neste projeto é implementada uma arquitetura de WAFs redundantes utilizando o conceito de diversidade a nível do sistema operativo, servidor web e da tecnologia WAF. Para avaliar o desempenho usamos ferramentas de análise de vulnerabilidades para executar testes de segurança e uma ferramenta de testes de carga para aplicações web para medir os tempos de resposta. A avaliação comparou resiliência da nossa arquitetura e o impacto no desempenho com outras configurações, com e sem WAFs