The Experts below are selected from a list of 96 Experts worldwide ranked by ideXlab platform

Nenad Jovanović - One of the best experts on this subject based on the ideXlab platform.

  • SecuBat : A Web Vulnerability Scanner
    WWW '06: Proceedings of the 15th international conference on World Wide Web, 2006
    Co-Authors: Stefan Kals, Engin Kirda, Christopher Kruegel, Nenad Jovanović
    Abstract:

    As the popularity of the web increases and web applications become tools of everyday use, the role of web security has been gaining imPortance as well. The last years have shown a significant increase in the number of web-based attacks. For example, there has been extensive press coverage of recent security incidences involving the loss of sensitive credit card information belonging to millions of customers.Many web application security vulnerabilities result from generic input validation problems. Examples of such vulnerabilities are SQL injection and Cross-Site Scripting (XSS). Although the majority of web vulnerabilities are easy to understand and to avoid, many web developers are, unfortunately, not security-aware. As a result, there exist many web sites on the Internet that are vulnerable.This paper demonstrates how easy it is for attackers to automatically discover and exploit application-level vulnerabilities in a large number of web applications. To this end, we developed SecuBat, a generic and modular web vulnerability Scanner that, similar to a Port Scanner, automatically analyzes web sites with the aim of finding exploitable SQL injection and XSS vulnerabilities. Using SecuBat, we were able to find many potentially vulnerable web sites. To verify the accuracy of SecuBat, we picked one hundred interesting web sites from the potential victim list for further analysis and confirmed exploitable flaws in the identified web pages. Among our victims were well-known global companies and a finance ministry. Of course, we notified the administrators of vulnerable sites about potential security problems. More than fifty responded to request additional information or to rePort that the security hole was closed.

Yoshinori Suzuki - One of the best experts on this subject based on the ideXlab platform.

  • probe delay based adaptive Port scanning for iot devices with private ip address behind nat
    IEEE Network, 2020
    Co-Authors: Fengxiao Tang, Yuichi Kawamoto, Nei Kato, Kazuto Yano, Yoshinori Suzuki
    Abstract:

    Recently, the explosive increase in the number of IoT devices makes the IoT becomes extremely large-scaled, and the security of such a large scale IoT emerges as a big challenge. As a classic security technique, the Port scan is widely used around the world. However, as IP resources are limited, a large number of devices are located in the LAN or WLAN behind the NAT which cannot be directly accessed by the Port Scanner. Furthermore, Port scanning generated a tremendous number of probe and response packets which may cause heavy traffic load and frequent congestion. To conquer those problems, in this article, we first propose a reverse proxy based NAT penetration system for scanning Ports behind NAT. Based on the NAT penetration system, we proposed a probe delay based adaptive scanning algorithm referred to as ProDASA, which adaptively changes Port scanning frequency and scanning methods to balance the network performance and security requirements of the IoT. The experiment in a real environment demonstrates the feasibility of the proposed NAT penetration system and the computational simulation with multiple virtual devices shows the advantage of our proposed ProDASA in terms of both network performance and security by comparing with a conventional method.

Stefan Kals - One of the best experts on this subject based on the ideXlab platform.

  • SecuBat : A Web Vulnerability Scanner
    WWW '06: Proceedings of the 15th international conference on World Wide Web, 2006
    Co-Authors: Stefan Kals, Engin Kirda, Christopher Kruegel, Nenad Jovanović
    Abstract:

    As the popularity of the web increases and web applications become tools of everyday use, the role of web security has been gaining imPortance as well. The last years have shown a significant increase in the number of web-based attacks. For example, there has been extensive press coverage of recent security incidences involving the loss of sensitive credit card information belonging to millions of customers.Many web application security vulnerabilities result from generic input validation problems. Examples of such vulnerabilities are SQL injection and Cross-Site Scripting (XSS). Although the majority of web vulnerabilities are easy to understand and to avoid, many web developers are, unfortunately, not security-aware. As a result, there exist many web sites on the Internet that are vulnerable.This paper demonstrates how easy it is for attackers to automatically discover and exploit application-level vulnerabilities in a large number of web applications. To this end, we developed SecuBat, a generic and modular web vulnerability Scanner that, similar to a Port Scanner, automatically analyzes web sites with the aim of finding exploitable SQL injection and XSS vulnerabilities. Using SecuBat, we were able to find many potentially vulnerable web sites. To verify the accuracy of SecuBat, we picked one hundred interesting web sites from the potential victim list for further analysis and confirmed exploitable flaws in the identified web pages. Among our victims were well-known global companies and a finance ministry. Of course, we notified the administrators of vulnerable sites about potential security problems. More than fifty responded to request additional information or to rePort that the security hole was closed.

Pokorný Josef - One of the best experts on this subject based on the ideXlab platform.

  • Location of attacker attempting unauthorized access to operating system
    Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií, 2013
    Co-Authors: Pokorný Josef
    Abstract:

    My master thesis estimates physical location of potential operating system attacker. It deals with basic methods of attack against operating system: spam and viruses, searching the Internet, Port scanning and operating system detection. The thesis disserts about a Port Scanner Nmap, a Port scanning detector Scanlogd and about a system log watch Swatch. The thesis deals with geolocation methods of potential operating system attacker. These geolocation methods are divided into an active and a passive types. The active methods measure delay in the Internet. The passive methods query the database. I mentioned a freely accessible Whois database and MaxMind databases. There is a program developed and practically tested. The program simulates an attacker beginning an attack by scanning Ports of target machine. The program works with dataset of real IP addresses. The program also detects the attack against operating system. The real and evaluated location of an attacker is got and then shown in a map. At the end there is a review of results and data comparison with colleagues

  • Location of attacker attempting unauthorized access to operating system
    Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií, 2013
    Co-Authors: Pokorný Josef
    Abstract:

    Předkládaná diplomová práce se zabývá určením fyzické polohy potenciálního útočníka na operační systém. Ve své práci zmiňuji základní způsoby útoku na operační systém: spam a viry, zjišťování informací o síti dostupných na internetu, skenování Portů a detekce operačního systému. V práci popisuji užití programů: Port skener Nmap, detektor skenování Scanlogd a prohlížeč systémových logů Swatch. Zabýval jsem se metodami určení fyzické polohy útočící stanice. Geolokační metody rozdělujeme na aktivní a pasivní. Aktivní metody spočívají v měření zpoždění v Internetu. Pasivní metody spočívají v dotazech do databáze na hledanou IP adresu. Popsal jsem volně dostupnou databázi Whois a databáze MaxMind. Vytvořil jsem aplikaci, která simuluje útok metodou skenování Portů. Aplikace pracuje s datasetem reálných IP adres. Vytvořil jsem také aplikaci periodicky detekující útok. Skutečná poloha z datasetu a zjištěná poloha útočníka je potom zobrazena v mapě. Závěr práce se věnuje zhodnocení měření a porovnání naměřených dat s daty kolegů.My master thesis estimates physical location of potential operating system attacker. It deals with basic methods of attack against operating system: spam and viruses, searching the Internet, Port scanning and operating system detection. The thesis disserts about a Port Scanner Nmap, a Port scanning detector Scanlogd and about a system log watch Swatch. The thesis deals with geolocation methods of potential operating system attacker. These geolocation methods are divided into an active and a passive types. The active methods measure delay in the Internet. The passive methods query the database. I mentioned a freely accessible Whois database and MaxMind databases. There is a program developed and practically tested. The program simulates an attacker beginning an attack by scanning Ports of target machine. The program works with dataset of real IP addresses. The program also detects the attack against operating system. The real and evaluated location of an attacker is got and then shown in a map. At the end there is a review of results and data comparison with colleagues.

Julianto Julianto - One of the best experts on this subject based on the ideXlab platform.

  • analisa dan perancangan keamanan jaringan mikrotik menggunakan Port Scanner detection
    2020
    Co-Authors: Julianto Julianto
    Abstract:

    Pada saat perangakat kita terhubung ke internet (public) maka hal yang pertama harus perhatikan ialah perihal keamanan jaringan. Ada banyak jenis ancaman pada jaringan public seperti information/indentity theft, data loss aamp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp; manipulation, disruption of service. Dari begitu banyaknya tindak kejahatan jaringan yang paling ditakutkan ialah Port scanning. Port scanning merupakan aktivitas awal dari sebuah tindak kejahatan teknologi jaringan untuk memperoleh data dan informasi target sebelum melakukan serangan atau penyusupan. Tugas akhir ini dibuat dengan maksud untuk menganalisa dan merancang sebuah sistem keamanan jaringan dengan memanfaatkan Port Scanner detection yang terdapat pada router mikrotik. Penelitian ini nantinya akan menghasilkan sebuah penelitian beserta solusi yang dapat diterapkan pada keamanan jaringan untuk mencegah ancaman scanning ke perangkat kita. Saat pengujiannya penelitian akan mencoba melakukan scanning ke jaringan untuk memperoleh informasi router yang kemudian dengan menerapkan Port Scanner detection kita dapat menhadang serangan scanning yang dilakukan tadi. ********************************************************************** Pada saat perangakat kita terhubung ke internet (public) maka hal yang pertama harus perhatikan ialah perihal keamanan jaringan. Ada banyak jenis ancaman pada jaringan public seperti information/indentity theft, data loss aamp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp; manipulation, disruption of service. Dari begitu banyaknya tindak kejahatan jaringan yang paling ditakutkan ialah Port scanning. Port scanning merupakan aktivitas awal dari sebuah tindak kejahatan teknologi jaringan untuk memperoleh data dan informasi target sebelum melakukan serangan atau penyusupan. Tugas akhir ini dibuat dengan maksud untuk menganalisa dan merancang sebuah sistem keamanan jaringan dengan memanfaatkan Port Scanner detection yang terdapat pada router mikrotik. Penelitian ini nantinya akan menghasilkan sebuah penelitian beserta solusi yang dapat diterapkan pada keamanan jaringan untuk mencegah ancaman scanning ke perangkat kita. Saat pengujiannya penelitian akan mencoba melakukan scanning ke jaringan untuk memperoleh informasi router yang kemudian dengan menerapkan Port Scanner detection kita dapat menhadang serangan scanning yang dilakukan tadi.