The Experts below are selected from a list of 75 Experts worldwide ranked by ideXlab platform
Ahmed Serhrouchni - One of the best experts on this subject based on the ideXlab platform.
-
IAS - Improving Web Application Firewalls to detect advanced SQL injection attacks
2014 10th International Conference on Information Assurance and Security, 2014Co-Authors: Abdelhamid Makiou, Youcef Begriche, Ahmed SerhrouchniAbstract:Injections flaws which include SQL injection are the most prevalent security threats affecting Web applications[1]. To mitigate these attacks, Web Application Firewalls (WAFs) apply security rules in order to both inspect HTTP data streams and detect malicious HTTP transactions. Nevertheless, attackers can bypass WAF's rules by using sophisticated SQL injection techniques. In this paper, we introduce a novel approach to dissect the HTTP traffic and inspect complex SQL injection attacks. Our model is a hybrid Injection Prevention System (HIPS) which uses both a machine learning classifier and a pattern matching Inspection Engine based on reduced sets of security rules. Our Web Application Firewall architecture aims to optimize detection performances by using a prediction module that excludes legitimate requests from the Inspection process.
-
Hybrid Approach to Detect SQLi Attacks and Evasion Techniques
2014Co-Authors: Abdelhamid Makiou, Youcef Begriche, Ahmed SerhrouchniAbstract:—Injections flaws which include SQL injection are the most prevalent security threats affecting Web applications[1]. To mitigate these attacks, Web Application Firewalls (WAFs) apply security rules in order to both inspect HTTP data streams and detect malicious HTTP transactions. Nevertheless, attackers can bypass WAF's rules by using sophisticated SQL injection techniques. In this paper, we introduce a novel approach to dissect the HTTP traffic and inspect complex SQL injection attacks. Our model is a hybrid Injection Prevention System (HIPS) which uses both a machine learning classifier and a pattern matching Inspection Engine based on reduced sets of security rules.
-
Improving Web Application Firewalls to detect advanced SQL injection attacks
2014 10th International Conference on Information Assurance and Security, 2014Co-Authors: Abdelhamid Makiou, Youcef Begriche, Ahmed SerhrouchniAbstract:Injections flaws which include SQL injection are the most prevalent security threats affecting Web applications[1]. To mitigate these attacks, Web Application Firewalls (WAFs) apply security rules in order to both inspect HTTP data streams and detect malicious HTTP transactions. Nevertheless, attackers can bypass WAF's rules by using sophisticated SQL injection techniques. In this paper, we introduce a novel approach to dissect the HTTP traffic and inspect complex SQL injection attacks. Our model is a hybrid Injection Prevention System (HIPS) which uses both a machine learning classifier and a pattern matching Inspection Engine based on reduced sets of security rules. Our Web Application Firewall architecture aims to optimize detection performances by using a prediction module that excludes legitimate requests from the Inspection process.
-
CollaborateCom - Hybrid approach to detect SQLi attacks and evasion techniques
Proceedings of the 10th IEEE International Conference on Collaborative Computing: Networking Applications and Worksharing, 2014Co-Authors: Abdelhamid Makiou, Youcef Begriche, Ahmed SerhrouchniAbstract:International audience—Injections flaws which include SQL injection are the most prevalent security threats affecting Web applications[1]. To mitigate these attacks, Web Application Firewalls (WAFs) apply security rules in order to both inspect HTTP data streams and detect malicious HTTP transactions. Nevertheless, attackers can bypass WAF's rules by using sophisticated SQL injection techniques. In this paper, we introduce a novel approach to dissect the HTTP traffic and inspect complex SQL injection attacks. Our model is a hybrid Injection Prevention System (HIPS) which uses both a machine learning classifier and a pattern matching Inspection Engine based on reduced sets of security rules
Michela Becchi - One of the best experts on this subject based on the ideXlab platform.
-
O3FA: A scalable finite automata-based pattern-matching Engine for out-of-order deep packet Inspection
2016 ACM/IEEE Symposium on Architectures for Networking and Communications Systems (ANCS), 2016Co-Authors: Xiaodong Yu, Danfeng Yao, Wu-chun Feng, Michela BecchiAbstract:To match the signatures of malicious traffic across packet boundaries, network-intrusion detection (and prevention) systems (NIDS) typically perform pattern matching after flow reassembly or packet reordering. However, this may lead to the need for large packet buffers, making detection vulnerable to denial-of-service (DoS) attacks, whereby attackers exhaust the buffer capacity by sending long sequences of out-of-order packets. While researchers have proposed solutions for exact-match patterns, regular-expression matching on out-of-order packets is still an open problem. Specifically, a key challenge is the matching of complex sub-patterns (such as repetitions of wildcards matched at the boundary between packets). Our proposed approach leverages the insight that various segments matching the same repetitive sub-pattern are logically equivalent to the regular-expression matching Engine, and thus, interchanging them would not affect the final result. In this paper, we present O3FA, a new finite automata-based, deep packet-Inspection Engine to perform regular-expression matching on out-of-order packets without requiring flow reassembly. O3FA consists of a deterministic finite automaton (FA) coupled with a set of prefix-/suffix-FA, which allows processing out-of-order packets on the fly. We present our design, optimization, and evaluation for the O3FA Engine. Our experiments show that our design requires 20×-4000× less buffer space than conventional buffering-and-reassembling schemes on various datasets and that it can process packets in real-time, i.e., without reassembly.
Abdelhamid Makiou - One of the best experts on this subject based on the ideXlab platform.
-
IAS - Improving Web Application Firewalls to detect advanced SQL injection attacks
2014 10th International Conference on Information Assurance and Security, 2014Co-Authors: Abdelhamid Makiou, Youcef Begriche, Ahmed SerhrouchniAbstract:Injections flaws which include SQL injection are the most prevalent security threats affecting Web applications[1]. To mitigate these attacks, Web Application Firewalls (WAFs) apply security rules in order to both inspect HTTP data streams and detect malicious HTTP transactions. Nevertheless, attackers can bypass WAF's rules by using sophisticated SQL injection techniques. In this paper, we introduce a novel approach to dissect the HTTP traffic and inspect complex SQL injection attacks. Our model is a hybrid Injection Prevention System (HIPS) which uses both a machine learning classifier and a pattern matching Inspection Engine based on reduced sets of security rules. Our Web Application Firewall architecture aims to optimize detection performances by using a prediction module that excludes legitimate requests from the Inspection process.
-
Hybrid Approach to Detect SQLi Attacks and Evasion Techniques
2014Co-Authors: Abdelhamid Makiou, Youcef Begriche, Ahmed SerhrouchniAbstract:—Injections flaws which include SQL injection are the most prevalent security threats affecting Web applications[1]. To mitigate these attacks, Web Application Firewalls (WAFs) apply security rules in order to both inspect HTTP data streams and detect malicious HTTP transactions. Nevertheless, attackers can bypass WAF's rules by using sophisticated SQL injection techniques. In this paper, we introduce a novel approach to dissect the HTTP traffic and inspect complex SQL injection attacks. Our model is a hybrid Injection Prevention System (HIPS) which uses both a machine learning classifier and a pattern matching Inspection Engine based on reduced sets of security rules.
-
Improving Web Application Firewalls to detect advanced SQL injection attacks
2014 10th International Conference on Information Assurance and Security, 2014Co-Authors: Abdelhamid Makiou, Youcef Begriche, Ahmed SerhrouchniAbstract:Injections flaws which include SQL injection are the most prevalent security threats affecting Web applications[1]. To mitigate these attacks, Web Application Firewalls (WAFs) apply security rules in order to both inspect HTTP data streams and detect malicious HTTP transactions. Nevertheless, attackers can bypass WAF's rules by using sophisticated SQL injection techniques. In this paper, we introduce a novel approach to dissect the HTTP traffic and inspect complex SQL injection attacks. Our model is a hybrid Injection Prevention System (HIPS) which uses both a machine learning classifier and a pattern matching Inspection Engine based on reduced sets of security rules. Our Web Application Firewall architecture aims to optimize detection performances by using a prediction module that excludes legitimate requests from the Inspection process.
-
CollaborateCom - Hybrid approach to detect SQLi attacks and evasion techniques
Proceedings of the 10th IEEE International Conference on Collaborative Computing: Networking Applications and Worksharing, 2014Co-Authors: Abdelhamid Makiou, Youcef Begriche, Ahmed SerhrouchniAbstract:International audience—Injections flaws which include SQL injection are the most prevalent security threats affecting Web applications[1]. To mitigate these attacks, Web Application Firewalls (WAFs) apply security rules in order to both inspect HTTP data streams and detect malicious HTTP transactions. Nevertheless, attackers can bypass WAF's rules by using sophisticated SQL injection techniques. In this paper, we introduce a novel approach to dissect the HTTP traffic and inspect complex SQL injection attacks. Our model is a hybrid Injection Prevention System (HIPS) which uses both a machine learning classifier and a pattern matching Inspection Engine based on reduced sets of security rules
Youcef Begriche - One of the best experts on this subject based on the ideXlab platform.
-
IAS - Improving Web Application Firewalls to detect advanced SQL injection attacks
2014 10th International Conference on Information Assurance and Security, 2014Co-Authors: Abdelhamid Makiou, Youcef Begriche, Ahmed SerhrouchniAbstract:Injections flaws which include SQL injection are the most prevalent security threats affecting Web applications[1]. To mitigate these attacks, Web Application Firewalls (WAFs) apply security rules in order to both inspect HTTP data streams and detect malicious HTTP transactions. Nevertheless, attackers can bypass WAF's rules by using sophisticated SQL injection techniques. In this paper, we introduce a novel approach to dissect the HTTP traffic and inspect complex SQL injection attacks. Our model is a hybrid Injection Prevention System (HIPS) which uses both a machine learning classifier and a pattern matching Inspection Engine based on reduced sets of security rules. Our Web Application Firewall architecture aims to optimize detection performances by using a prediction module that excludes legitimate requests from the Inspection process.
-
Hybrid Approach to Detect SQLi Attacks and Evasion Techniques
2014Co-Authors: Abdelhamid Makiou, Youcef Begriche, Ahmed SerhrouchniAbstract:—Injections flaws which include SQL injection are the most prevalent security threats affecting Web applications[1]. To mitigate these attacks, Web Application Firewalls (WAFs) apply security rules in order to both inspect HTTP data streams and detect malicious HTTP transactions. Nevertheless, attackers can bypass WAF's rules by using sophisticated SQL injection techniques. In this paper, we introduce a novel approach to dissect the HTTP traffic and inspect complex SQL injection attacks. Our model is a hybrid Injection Prevention System (HIPS) which uses both a machine learning classifier and a pattern matching Inspection Engine based on reduced sets of security rules.
-
Improving Web Application Firewalls to detect advanced SQL injection attacks
2014 10th International Conference on Information Assurance and Security, 2014Co-Authors: Abdelhamid Makiou, Youcef Begriche, Ahmed SerhrouchniAbstract:Injections flaws which include SQL injection are the most prevalent security threats affecting Web applications[1]. To mitigate these attacks, Web Application Firewalls (WAFs) apply security rules in order to both inspect HTTP data streams and detect malicious HTTP transactions. Nevertheless, attackers can bypass WAF's rules by using sophisticated SQL injection techniques. In this paper, we introduce a novel approach to dissect the HTTP traffic and inspect complex SQL injection attacks. Our model is a hybrid Injection Prevention System (HIPS) which uses both a machine learning classifier and a pattern matching Inspection Engine based on reduced sets of security rules. Our Web Application Firewall architecture aims to optimize detection performances by using a prediction module that excludes legitimate requests from the Inspection process.
-
CollaborateCom - Hybrid approach to detect SQLi attacks and evasion techniques
Proceedings of the 10th IEEE International Conference on Collaborative Computing: Networking Applications and Worksharing, 2014Co-Authors: Abdelhamid Makiou, Youcef Begriche, Ahmed SerhrouchniAbstract:International audience—Injections flaws which include SQL injection are the most prevalent security threats affecting Web applications[1]. To mitigate these attacks, Web Application Firewalls (WAFs) apply security rules in order to both inspect HTTP data streams and detect malicious HTTP transactions. Nevertheless, attackers can bypass WAF's rules by using sophisticated SQL injection techniques. In this paper, we introduce a novel approach to dissect the HTTP traffic and inspect complex SQL injection attacks. Our model is a hybrid Injection Prevention System (HIPS) which uses both a machine learning classifier and a pattern matching Inspection Engine based on reduced sets of security rules
Xiaodong Yu - One of the best experts on this subject based on the ideXlab platform.
-
O3FA: A scalable finite automata-based pattern-matching Engine for out-of-order deep packet Inspection
2016 ACM/IEEE Symposium on Architectures for Networking and Communications Systems (ANCS), 2016Co-Authors: Xiaodong Yu, Danfeng Yao, Wu-chun Feng, Michela BecchiAbstract:To match the signatures of malicious traffic across packet boundaries, network-intrusion detection (and prevention) systems (NIDS) typically perform pattern matching after flow reassembly or packet reordering. However, this may lead to the need for large packet buffers, making detection vulnerable to denial-of-service (DoS) attacks, whereby attackers exhaust the buffer capacity by sending long sequences of out-of-order packets. While researchers have proposed solutions for exact-match patterns, regular-expression matching on out-of-order packets is still an open problem. Specifically, a key challenge is the matching of complex sub-patterns (such as repetitions of wildcards matched at the boundary between packets). Our proposed approach leverages the insight that various segments matching the same repetitive sub-pattern are logically equivalent to the regular-expression matching Engine, and thus, interchanging them would not affect the final result. In this paper, we present O3FA, a new finite automata-based, deep packet-Inspection Engine to perform regular-expression matching on out-of-order packets without requiring flow reassembly. O3FA consists of a deterministic finite automaton (FA) coupled with a set of prefix-/suffix-FA, which allows processing out-of-order packets on the fly. We present our design, optimization, and evaluation for the O3FA Engine. Our experiments show that our design requires 20×-4000× less buffer space than conventional buffering-and-reassembling schemes on various datasets and that it can process packets in real-time, i.e., without reassembly.