The Experts below are selected from a list of 66 Experts worldwide ranked by ideXlab platform
Alberto Bartoli - One of the best experts on this subject based on the ideXlab platform.
-
A Framework for Large-Scale Detection of Web Site Defacements
ACM Transactions on Internet Technology, 2010Co-Authors: Alberto Bartoli, Giorgio Davanzo, Eric MedvetAbstract:Web Site Defacement, the process of introducing unauthorized modifications to a Web Site, is a very common form of attack. In this paper we describe and evaluate experimentally a framework that may constitute the basis for a Defacement detection service capable of monitoring thousands of remote Web Sites systematically and automatically. In our framework an organization may join the service by simply providing the URLs of the resources to be monitored along with the contact point of an administrator. The monitored organization may thus take advantage of the service with just a few mouse clicks, without installing any software locally or changing its own daily operational processes. Our approach is based on anomaly detection and allows monitoring the integrity of many remote Web resources automatically while remaining fully decoupled from them, in particular, without requiring any prior knowledge about those resources. We evaluated our approach over a selection of dynamic resources and a set of publicly available Defacements. The results are very satisfactory: all attacks are detected while keeping false positives to a minimum. We also assessed performance and scalability of our proposal and we found that it may indeed constitute the basis for actually deploying the proposed service on a large scale.
-
The Reaction Time to Web Site Defacements
IEEE Internet Computing, 2009Co-Authors: Alberto Bartoli, Giorgio Davanzo, Eric MedvetAbstract:Web Site Defacement has become a common threat for organizations exposed on the Web. Several statistics indicate the occurrence rate of these incidents but not how long these Defacements typically last. The authors present the results of a two-month study of more than 62,000 Defacements to determine whether and when a reaction to a Defacement occurs. Such reaction times tend to be unacceptably long - often several days - and with a long-tailed distribution.
-
SEC - A Comparative Study of Anomaly Detection Techniques in Web Site Defacement Detection
Proceedings of The Ifip Tc 11 23rd International Information Security Conference, 2008Co-Authors: Giorgio Davanzo, Eric Medvet, Alberto BartoliAbstract:Web Site Defacement, the process of introducing unauthorized modifications to a Web Site, is a very common form of attack. Detecting such events automatically is very difficult because Web pages are highly dynamic and their degree of dynamism, as well as their typical content and appearance, may vary widely across different pages. Anomaly based detection can be a feasible and effective solution for this task because it does not require any prior knowledge about the page to be monitored. This study enables gaining further insights into the problem of automatic detection of Web Defacements.We want to ascertain whether existing techniques for anomaly intrusion detection may be applied to this problem and we want to assess pros and cons of incorporating domain knowledge into the detection algorithm.
-
a comparative study of anomaly detection techniques in Web Site Defacement detection
Information Security Conference, 2008Co-Authors: Giorgio Davanzo, Eric Medvet, Alberto BartoliAbstract:Web Site Defacement, the process of introducing unauthorized modifications to a Web Site, is a very common form of attack. Detecting such events automatically is very difficult because Web pages are highly dynamic and their degree of dynamism, as well as their typical content and appearance, may vary widely across different pages. Anomaly based detection can be a feasible and effective solution for this task because it does not require any prior knowledge about the page to be monitored. This study enables gaining further insights into the problem of automatic detection of Web Defacements.We want to ascertain whether existing techniques for anomaly intrusion detection may be applied to this problem and we want to assess pros and cons of incorporating domain knowledge into the detection algorithm.
-
IAS - Detection of Web Defacements by means of Genetic Programming
Third International Symposium on Information Assurance and Security, 2007Co-Authors: Eric Medvet, Cyril Fillon, Alberto BartoliAbstract:Web Site Defacement, the process of introducing unauthorized modifications to a Web Site, is a very common form of attack. Detecting such events automatically is very difficult because Web pages are highly dynamic and their degree of dynamism may vary widely across different pages. In this paper we propose a novel detection approach based on genetic programming (GP), an established evolutionary computation paradigm for automatic generation of algorithms. What makes GP particularly attractive in this context is that it does not rely on any domain-specific knowledge, whose description and synthesis is invariably a hard job. In a preliminary learning phase, GP builds an algorithm based on a sequence of readings of the remote page to be monitored and on a sample set of attacks. Then, we monitor the remote page at regular intervals and apply that algorithm, which raises an alert when a suspect modification is found. We developed a prototype based on a broader Web detection framework we proposed earlier and we tested our approach over a dataset of 15 dynamic Web pages, observed for about a month, and a collection of real Web Defacements. We compared the results to those of a solution we developed earlier, whose design embedded a substantial amount of domain specific knowledge, and the results clearly show that GP may be an effective approach for this job.
Eric Medvet - One of the best experts on this subject based on the ideXlab platform.
-
A Framework for Large-Scale Detection of Web Site Defacements
ACM Transactions on Internet Technology, 2010Co-Authors: Alberto Bartoli, Giorgio Davanzo, Eric MedvetAbstract:Web Site Defacement, the process of introducing unauthorized modifications to a Web Site, is a very common form of attack. In this paper we describe and evaluate experimentally a framework that may constitute the basis for a Defacement detection service capable of monitoring thousands of remote Web Sites systematically and automatically. In our framework an organization may join the service by simply providing the URLs of the resources to be monitored along with the contact point of an administrator. The monitored organization may thus take advantage of the service with just a few mouse clicks, without installing any software locally or changing its own daily operational processes. Our approach is based on anomaly detection and allows monitoring the integrity of many remote Web resources automatically while remaining fully decoupled from them, in particular, without requiring any prior knowledge about those resources. We evaluated our approach over a selection of dynamic resources and a set of publicly available Defacements. The results are very satisfactory: all attacks are detected while keeping false positives to a minimum. We also assessed performance and scalability of our proposal and we found that it may indeed constitute the basis for actually deploying the proposed service on a large scale.
-
The Reaction Time to Web Site Defacements
IEEE Internet Computing, 2009Co-Authors: Alberto Bartoli, Giorgio Davanzo, Eric MedvetAbstract:Web Site Defacement has become a common threat for organizations exposed on the Web. Several statistics indicate the occurrence rate of these incidents but not how long these Defacements typically last. The authors present the results of a two-month study of more than 62,000 Defacements to determine whether and when a reaction to a Defacement occurs. Such reaction times tend to be unacceptably long - often several days - and with a long-tailed distribution.
-
SEC - A Comparative Study of Anomaly Detection Techniques in Web Site Defacement Detection
Proceedings of The Ifip Tc 11 23rd International Information Security Conference, 2008Co-Authors: Giorgio Davanzo, Eric Medvet, Alberto BartoliAbstract:Web Site Defacement, the process of introducing unauthorized modifications to a Web Site, is a very common form of attack. Detecting such events automatically is very difficult because Web pages are highly dynamic and their degree of dynamism, as well as their typical content and appearance, may vary widely across different pages. Anomaly based detection can be a feasible and effective solution for this task because it does not require any prior knowledge about the page to be monitored. This study enables gaining further insights into the problem of automatic detection of Web Defacements.We want to ascertain whether existing techniques for anomaly intrusion detection may be applied to this problem and we want to assess pros and cons of incorporating domain knowledge into the detection algorithm.
-
a comparative study of anomaly detection techniques in Web Site Defacement detection
Information Security Conference, 2008Co-Authors: Giorgio Davanzo, Eric Medvet, Alberto BartoliAbstract:Web Site Defacement, the process of introducing unauthorized modifications to a Web Site, is a very common form of attack. Detecting such events automatically is very difficult because Web pages are highly dynamic and their degree of dynamism, as well as their typical content and appearance, may vary widely across different pages. Anomaly based detection can be a feasible and effective solution for this task because it does not require any prior knowledge about the page to be monitored. This study enables gaining further insights into the problem of automatic detection of Web Defacements.We want to ascertain whether existing techniques for anomaly intrusion detection may be applied to this problem and we want to assess pros and cons of incorporating domain knowledge into the detection algorithm.
-
Techniques for large-scale automatic detection of Web Site Defacements.
2008Co-Authors: Eric MedvetAbstract:Web Site Defacement, the process of introducing unauthorized modifications to a Web Site, is a very common form of attack. This thesis describes the design and experimental evaluation of a framework that may constitute the basis for a Defacement detection service capable of monitoring thousands of remote Web Sites systematically and automatically. With this framework an organization may join the service by simply providing the URL of the resource to be monitored along with the contact point of an administrator. The monitored organization may thus take advantage of the service with just a few mouse clicks, without installing any software locally nor changing its own daily operational processes. The main proposed approach is based on anomaly detection and allows monitoring the integrity of many remote Web resources automatically while remaining fully decoupled from them, in particular, without requiring any prior knowledge about those resources. During a preliminary learning phase a profile of the monitored resource is built automatically. Then, while monitoring, the remote resource is retrieved periodically and an alert is generated whenever something “unusual” shows up. The thesis discusses about the effectiveness of the approach in terms of accuracy of detection—i.e., missed detections and false alarms. The thesis also considers the problem of misclassified readings in the learning set. The effectiveness of anomaly detection approach, and hence of the proposed framework, bases on the assumption that the profile is computed starting from a learning set which is not corrupted by attacks; this assumption is often taken for granted. The influence of leaning set corruption on our framework effectiveness is assessed and a procedure aimed at discovering when a given unknown learning set is corrupted by positive readings is proposed and evaluated experimentally. An approach to automatic Defacement detection based on Genetic Programming (GP), an automatic method for creating computer programs by means of artificial evolution, is proposed and evaluated experimentally. Moreover, a set of techniques that have been used in literature for designing several host-based or network-based Intrusion Detection Systems are considered and evaluated experimentally, in comparison with the proposed approach. Finally, the thesis presents the findings of a large-scale study on reaction time to Web Site Defacement. There exist several statistics that indicate the number of incidents of this sort but there is a crucial piece of information still lacking: the typical duration of a Defacement. A two months monitoring activity has been performed over more than 62000 Defacements in order to figure out whether and when a reaction to the Defacement is taken. It is shown that such time tends to be unacceptably long—in the order of several days—and with a long-tailed distribution.
Giorgio Davanzo - One of the best experts on this subject based on the ideXlab platform.
-
A Framework for Large-Scale Detection of Web Site Defacements
ACM Transactions on Internet Technology, 2010Co-Authors: Alberto Bartoli, Giorgio Davanzo, Eric MedvetAbstract:Web Site Defacement, the process of introducing unauthorized modifications to a Web Site, is a very common form of attack. In this paper we describe and evaluate experimentally a framework that may constitute the basis for a Defacement detection service capable of monitoring thousands of remote Web Sites systematically and automatically. In our framework an organization may join the service by simply providing the URLs of the resources to be monitored along with the contact point of an administrator. The monitored organization may thus take advantage of the service with just a few mouse clicks, without installing any software locally or changing its own daily operational processes. Our approach is based on anomaly detection and allows monitoring the integrity of many remote Web resources automatically while remaining fully decoupled from them, in particular, without requiring any prior knowledge about those resources. We evaluated our approach over a selection of dynamic resources and a set of publicly available Defacements. The results are very satisfactory: all attacks are detected while keeping false positives to a minimum. We also assessed performance and scalability of our proposal and we found that it may indeed constitute the basis for actually deploying the proposed service on a large scale.
-
The Reaction Time to Web Site Defacements
IEEE Internet Computing, 2009Co-Authors: Alberto Bartoli, Giorgio Davanzo, Eric MedvetAbstract:Web Site Defacement has become a common threat for organizations exposed on the Web. Several statistics indicate the occurrence rate of these incidents but not how long these Defacements typically last. The authors present the results of a two-month study of more than 62,000 Defacements to determine whether and when a reaction to a Defacement occurs. Such reaction times tend to be unacceptably long - often several days - and with a long-tailed distribution.
-
The Reaction Time to Web Site Defacements
'Institute of Electrical and Electronics Engineers (IEEE)', 2009Co-Authors: Bartoli A., Giorgio Davanzo, Medvet E.Abstract:Web Site Defacement has become a common threat for organizations exposed on the Web. There exist several statistics that indicate the number of incidents of this sort but there is a crucial piece of information still lacking: the typical duration of a Defacement. Clearly, a Defacement lasting one week is much more harmful than one of few minutes. In this paper we present the results of a two months monitoring activity that we performed over more than 62000 Defacements in order to figure out whether and when} a reaction to the Defacement is taken. We show that such time tends to be unacceptably long---in the order of several days---and with a long-tailed distribution. We believe our findings may improve the understanding of this phenomenon and highlight issues deserving attention by the research community
-
SEC - A Comparative Study of Anomaly Detection Techniques in Web Site Defacement Detection
Proceedings of The Ifip Tc 11 23rd International Information Security Conference, 2008Co-Authors: Giorgio Davanzo, Eric Medvet, Alberto BartoliAbstract:Web Site Defacement, the process of introducing unauthorized modifications to a Web Site, is a very common form of attack. Detecting such events automatically is very difficult because Web pages are highly dynamic and their degree of dynamism, as well as their typical content and appearance, may vary widely across different pages. Anomaly based detection can be a feasible and effective solution for this task because it does not require any prior knowledge about the page to be monitored. This study enables gaining further insights into the problem of automatic detection of Web Defacements.We want to ascertain whether existing techniques for anomaly intrusion detection may be applied to this problem and we want to assess pros and cons of incorporating domain knowledge into the detection algorithm.
-
a comparative study of anomaly detection techniques in Web Site Defacement detection
Information Security Conference, 2008Co-Authors: Giorgio Davanzo, Eric Medvet, Alberto BartoliAbstract:Web Site Defacement, the process of introducing unauthorized modifications to a Web Site, is a very common form of attack. Detecting such events automatically is very difficult because Web pages are highly dynamic and their degree of dynamism, as well as their typical content and appearance, may vary widely across different pages. Anomaly based detection can be a feasible and effective solution for this task because it does not require any prior knowledge about the page to be monitored. This study enables gaining further insights into the problem of automatic detection of Web Defacements.We want to ascertain whether existing techniques for anomaly intrusion detection may be applied to this problem and we want to assess pros and cons of incorporating domain knowledge into the detection algorithm.
Bartoli A. - One of the best experts on this subject based on the ideXlab platform.
-
The Reaction Time to Web Site Defacements
'Institute of Electrical and Electronics Engineers (IEEE)', 2009Co-Authors: Bartoli A., Giorgio Davanzo, Medvet E.Abstract:Web Site Defacement has become a common threat for organizations exposed on the Web. There exist several statistics that indicate the number of incidents of this sort but there is a crucial piece of information still lacking: the typical duration of a Defacement. Clearly, a Defacement lasting one week is much more harmful than one of few minutes. In this paper we present the results of a two months monitoring activity that we performed over more than 62000 Defacements in order to figure out whether and when} a reaction to the Defacement is taken. We show that such time tends to be unacceptably long---in the order of several days---and with a long-tailed distribution. We believe our findings may improve the understanding of this phenomenon and highlight issues deserving attention by the research community
-
Detection of Web Defacements by means of Genetic Programming
'Institute of Electrical and Electronics Engineers (IEEE)', 2007Co-Authors: Medvet E., Fillon C, Bartoli A.Abstract:Web Site Defacement, the process of introducing unauthorized modifications to a Web Site, is a very common form of attack. Detecting such events automatically is very difficult because Web pages are highly dynamic and their degree of dynamism may vary widely across different pages. In this paper we propose a novel detection approach based on genetic programming (GP), an established evolutionary computation paradigm for automatic generation of algorithms. What makes GP particularly attractive in this context is that it does not rely on any domain-specific knowledge, whose description and synthesis is invariably a hard job. In a preliminary learning phase, GP builds an algorithm based on a sequence of readings of the remote page to be monitored and on a sample set of attacks. Then, we monitor the remote page at regular intervals and apply that algorithm, which raises an alert when a suspect modification is found. We developed a prototype based on a broader Web detection framework we proposed earlier and we tested our approach over a dataset of 15 dynamic Web pages, observed for about a month, and a collection of real Web Defacements. We compared the results to those of a solution we developed earlier, whose design embedded a substantial amount of domain specific knowledge, and the results clearly show that GP may be an effective approach for this job
Medvet E. - One of the best experts on this subject based on the ideXlab platform.
-
The Reaction Time to Web Site Defacements
'Institute of Electrical and Electronics Engineers (IEEE)', 2009Co-Authors: Bartoli A., Giorgio Davanzo, Medvet E.Abstract:Web Site Defacement has become a common threat for organizations exposed on the Web. There exist several statistics that indicate the number of incidents of this sort but there is a crucial piece of information still lacking: the typical duration of a Defacement. Clearly, a Defacement lasting one week is much more harmful than one of few minutes. In this paper we present the results of a two months monitoring activity that we performed over more than 62000 Defacements in order to figure out whether and when} a reaction to the Defacement is taken. We show that such time tends to be unacceptably long---in the order of several days---and with a long-tailed distribution. We believe our findings may improve the understanding of this phenomenon and highlight issues deserving attention by the research community
-
Detection of Web Defacements by means of Genetic Programming
'Institute of Electrical and Electronics Engineers (IEEE)', 2007Co-Authors: Medvet E., Fillon C, Bartoli A.Abstract:Web Site Defacement, the process of introducing unauthorized modifications to a Web Site, is a very common form of attack. Detecting such events automatically is very difficult because Web pages are highly dynamic and their degree of dynamism may vary widely across different pages. In this paper we propose a novel detection approach based on genetic programming (GP), an established evolutionary computation paradigm for automatic generation of algorithms. What makes GP particularly attractive in this context is that it does not rely on any domain-specific knowledge, whose description and synthesis is invariably a hard job. In a preliminary learning phase, GP builds an algorithm based on a sequence of readings of the remote page to be monitored and on a sample set of attacks. Then, we monitor the remote page at regular intervals and apply that algorithm, which raises an alert when a suspect modification is found. We developed a prototype based on a broader Web detection framework we proposed earlier and we tested our approach over a dataset of 15 dynamic Web pages, observed for about a month, and a collection of real Web Defacements. We compared the results to those of a solution we developed earlier, whose design embedded a substantial amount of domain specific knowledge, and the results clearly show that GP may be an effective approach for this job