Improving the Quality of Protection of Web Application Firewalls by a Simplified Taxonomy of Web Attacks

  • Conference paper
Advances in Information Security and Its Application (ISA 2009)

Part of the book series: Communications in Computer and Information Science ((CCIS,volume 36))

Included in the following conference series:

Abstract

Nowadays, with over 70% of attacks carried out over the web application level, organizations need all the help they can get in making their system secure. Web Application Firewalls (WAFs) are among the tools that are commonly used for the prevention of Web attacks. However, the WAFs provide very little protection on their own. In order to become useful, they must be configured with rules. Unfortunately, the rule configuration process is not easy and error-prone, thus the quality of protection(QoP) of WAFs is still behind our expectations. In this paper, we investigate the current WAFs and point out some of their problems regarding about the poor QoP. We then analyze the origins of these problems and propose two decision modules, the attack-decision module and priority-decision module based on a proposed simplified taxonomy of web attacks which are helpful for improving the QoP of WAFs. Finally, we conclude our work and show future interests to extend our modules to IDS systems.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Subscribe and save

Springer+ Basic
EUR 32.99 /Month
  • Get 10 units per month
  • Download Article/Chapter or Ebook
  • 1 Unit = 1 Article or 1 Chapter
  • Cancel anytime
Subscribe now

Buy Now

Chapter
EUR 29.95
Price includes VAT (Germany)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
EUR 42.79
Price includes VAT (Germany)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
EUR 53.49
Price includes VAT (Germany)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free ship** worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

Similar content being viewed by others

References

  1. ModSecurity Reference Manual Version 2.5.0, Breach Security, Inc., http://www.breach.com (February 19, 2008)

  2. Desmet, L., Piessens, F., Joosen, W., Verbaeten, P.: Bridging the Gap Between Web Application Firewalls and Web Application. In: FMSE 2006, Alexanadria, Virginia, USA, Novermber 3 (2006)

    Google Scholar 

  3. Byrne, P.: Application firewalls in a defence-in-depth design. Network Security 2006(9), 9–11 (2006)

    Article  Google Scholar 

  4. Forster, K.: Why Firewalls Fail to Protect Web Sites. Lockstep Systems, Inc. (2002)

    Google Scholar 

  5. Alvarez, G., Petrovic, S.: A Taxonomy of Web Attacks. In: Cueva Lovelle, J.M., Rodríguez, B.M.G., Gayo, J.E.L., Ruiz, M.d.P.P., Aguilar, L.J. (eds.) ICWE 2003. LNCS, vol. 2722, pp. 295–298. Springer, Heidelberg (2003)

    Chapter  Google Scholar 

  6. Lai, J.-Y., Wu, J.-S., Chen, S.-J., Wu, C.-H., Yang, C.-H.: Designing a Taxonomy of Web Attacks. In: 2008 International Conference on Convergence and Hybrid Information Technology, pp. 278–282 (2008)

    Google Scholar 

  7. Almgren, M., Barse, E.L., Jonsson, E.: Consolidation and Evaluation of IDS Taxonomies. In: Nordic Workshop on Secure IT Systems, Norway, October 15-17, 2003, pp. 57–70 (2003)

    Google Scholar 

  8. Howard, J.D., Longstaff, T.A.: A Common Language for Computer Security Incidents. Technical Report SAND98-8667, Sandia National Laboratories (1998)

    Google Scholar 

  9. Open Web Application Security Project (OWASP), Top ten most critical web application vulnerabilities (2005), http://www.owasp.org/documentation/topten.html

  10. Web Application Security Consortium, Web Application Firewall Evaluation Criteria, version 1.0 (January 2006), http://www.webappsec.org/projects/wafec/

  11. AQTronix-WebKnight, http://www.aqtronix.com/

  12. Breach-WebDefend, http://www.breach.com/products/webdefend.html

  13. Microsoft-ISA, http://www.microsoft.com/forefront/edgesecurity/isaserver/en/us/default.aspx

Download references

Author information

Authors and Affiliations

Authors

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2009 Springer-Verlag Berlin Heidelberg

About this paper

Cite this paper

Han, Y., Sakai, A., Hori, Y., Sakurai, K. (2009). Improving the Quality of Protection of Web Application Firewalls by a Simplified Taxonomy of Web Attacks. In: Park, J.H., Zhan, J., Lee, C., Wang, G., Kim, Th., Yeo, SS. (eds) Advances in Information Security and Its Application. ISA 2009. Communications in Computer and Information Science, vol 36. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-642-02633-1_14

Download citation

  • DOI: https://doi.org/10.1007/978-3-642-02633-1_14

  • Publisher Name: Springer, Berlin, Heidelberg

  • Print ISBN: 978-3-642-02632-4

  • Online ISBN: 978-3-642-02633-1

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics

Navigation