A deep learning assisted personalized deception system for countering web application attacks. (June 2022)
- Record Type:
- Journal Article
- Title:
- A deep learning assisted personalized deception system for countering web application attacks. (June 2022)
- Main Title:
- A deep learning assisted personalized deception system for countering web application attacks
- Authors:
- Shahid, Waleed Bin
Aslam, Baber
Abbas, Haider
Afzal, Hammad
Khalid, Saad Bin - Abstract:
- Abstract: Recent years have seen momentous growth in web attacks that has motivated researchers to come up with sophisticated techniques to tackle them. Lately, there has been growing interest to counter web attacks using deception techniques because they help in realizing attacker behavior, motives and abilities besides protecting the website. This paper proposes a complete high interaction web deception system which is assisted by a hybrid attack detection module comprising of a deep learning based classifier coupled with a cookie analysis engine that helps in attacker profiling. The detection module routes malicious HTTP (Hypertext Transfer Protocol) requests to the dockers based deception system which is controlled and managed by a docker controller. The proposed containerized approach makes the system efficient, reduces latency and enhances runtime development. The key feature of attacker profiling empowers the proposed system to deal with attackers carrying zero day attack payloads besides providing efficient session management and scenario based emulation. The proposed deception system caters for all major web application attacks and has high attacker engagement when tested in a real-time environment. Moreover, the proposed framework is scalable, agile and supports easy framework modification making it suitable even for IoT (Internet of Things) networks. The proposed attack detection module gave an accuracy of 99.94% and is less time consuming than other researchAbstract: Recent years have seen momentous growth in web attacks that has motivated researchers to come up with sophisticated techniques to tackle them. Lately, there has been growing interest to counter web attacks using deception techniques because they help in realizing attacker behavior, motives and abilities besides protecting the website. This paper proposes a complete high interaction web deception system which is assisted by a hybrid attack detection module comprising of a deep learning based classifier coupled with a cookie analysis engine that helps in attacker profiling. The detection module routes malicious HTTP (Hypertext Transfer Protocol) requests to the dockers based deception system which is controlled and managed by a docker controller. The proposed containerized approach makes the system efficient, reduces latency and enhances runtime development. The key feature of attacker profiling empowers the proposed system to deal with attackers carrying zero day attack payloads besides providing efficient session management and scenario based emulation. The proposed deception system caters for all major web application attacks and has high attacker engagement when tested in a real-time environment. Moreover, the proposed framework is scalable, agile and supports easy framework modification making it suitable even for IoT (Internet of Things) networks. The proposed attack detection module gave an accuracy of 99.94% and is less time consuming than other research works because of its profiling feature. These features give the proposed framework a high competitive edge over other web deception solutions. … (more)
- Is Part Of:
- Journal of information security and applications. Volume 67(2022)
- Journal:
- Journal of information security and applications
- Issue:
- Volume 67(2022)
- Issue Display:
- Volume 67, Issue 2022 (2022)
- Year:
- 2022
- Volume:
- 67
- Issue:
- 2022
- Issue Sort Value:
- 2022-0067-2022-0000
- Page Start:
- Page End:
- Publication Date:
- 2022-06
- Subjects:
- Web security -- Deception -- Web deception -- Web attacks -- HTTP -- Web honeypot
Computer security -- Periodicals
Information technology -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/ ↗
- DOI:
- 10.1016/j.jisa.2022.103169 ↗
- Languages:
- English
- ISSNs:
- 2214-2126
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - BLDSS-3PM
British Library STI - ELD Digital store - Ingest File:
- 21798.xml