@article{ART001050386},
author={kim,Sung-Rak},
title={A Study of Web Application Attack Detection extended ESM Agent},
journal={Journal of The Korea Society of Computer and Information},
issn={1598-849X},
year={2007},
volume={12},
number={1},
pages={163-170}
TY - JOUR
AU - kim,Sung-Rak
TI - A Study of Web Application Attack Detection extended ESM Agent
JO - Journal of The Korea Society of Computer and Information
PY - 2007
VL - 12
IS - 1
PB - The Korean Society Of Computer And Information
SP - 163
EP - 170
SN - 1598-849X
AB - Web attack uses structural, logical and coding error of web application rather than vulnerability to Web server itself. According to the Open Web Application Security Project (OWASP) published about ten types of the web application vulnerability to show the causes of hacking, the risk of hacking and the severity of damage are well known. The detection ability and response is important to deal with web hacking. Filtering methods like pattern matching and code modification are used for defense but these methods can not detect new types of attacks. Also though the security unit product like IDS or web application firewall can be used, these require a lot of money and efforts to operate and maintain, and security unit product is likely to generate false positive detection. In this research profiling method that attracts the structure of web application and the attributes of input parameters such as types and length is used, and by installing structural database of web application in advance it is possible that the lack of the validation of user input value check and the verification and attack detection is solved through using profiling identifier of database against illegal request. Integral security management system has been used in most institutes. Therefore even if additional unit security product is not applied, attacks against the web application will be able to be detected by showing the model, which the security monitoring log gathering agent of the integral security management system and the function of the detection of web application attack are combined.
KW - ESM;Intrusion Detection;Web Application
DO -
UR -
ER -
kim,Sung-Rak. (2007). A Study of Web Application Attack Detection extended ESM Agent. Journal of The Korea Society of Computer and Information, 12(1), 163-170.
kim,Sung-Rak. 2007, "A Study of Web Application Attack Detection extended ESM Agent", Journal of The Korea Society of Computer and Information, vol.12, no.1 pp.163-170.
kim,Sung-Rak "A Study of Web Application Attack Detection extended ESM Agent" Journal of The Korea Society of Computer and Information 12.1 pp.163-170 (2007) : 163.
kim,Sung-Rak. A Study of Web Application Attack Detection extended ESM Agent. 2007; 12(1), 163-170.
kim,Sung-Rak. "A Study of Web Application Attack Detection extended ESM Agent" Journal of The Korea Society of Computer and Information 12, no.1 (2007) : 163-170.
kim,Sung-Rak. A Study of Web Application Attack Detection extended ESM Agent. Journal of The Korea Society of Computer and Information, 12(1), 163-170.
kim,Sung-Rak. A Study of Web Application Attack Detection extended ESM Agent. Journal of The Korea Society of Computer and Information. 2007; 12(1) 163-170.
kim,Sung-Rak. A Study of Web Application Attack Detection extended ESM Agent. 2007; 12(1), 163-170.
kim,Sung-Rak. "A Study of Web Application Attack Detection extended ESM Agent" Journal of The Korea Society of Computer and Information 12, no.1 (2007) : 163-170.