Use of anomaly detection on client side to protect against web attacks

IP.com Prior Art Database Disclosure
IP.com Disclosure Number: IPCOM000191366D
Publication Date: 31-Dec-2009
More Like This Download

Publishing Venue

The IP.com Prior Art Database

Abstract

Use of anomaly detection on client side to protect against web attacks

Language

English (United States)

Document File

1 pages / 20.3 KB

This text was extracted from a PDF file.
This is the abbreviated version, containing approximately 72% of the total text.

Page 1 of 1

With the raise of web 2.0 applications we see more and more client side vulnerability in which a web application vulnerability is being used to attack one of the users of the web application.

    Today, automatic detections/preventions of this is mainly being done in two areas:
1. Server side protection (IPS/IDS) - Some of these protection mechanisms relies on signatures based rules or anomaly detection to identify attack requests. Beside having a lot of other problem - these protection mechanisms have a intrinsic problem

when trying to deal with some specific client side attacks such as dom based

cross-site scripting (in which the attack itself is not being sent to the server) and CSRF (in which the attack is delivered through one server tricking a victim into sending a seemingly legitimate request to another).
2. Client Side Protection - Today solution mainly use signature based protection, sandboxing and code execution to block or delete malicious scripts out of a response.

    Since many of these web attacks are done through textual modifications of the HTTP Requests, it is very easy to create a unique and new attack that will overcome many of the existing solutions
The flow will include 3 components:
1)

A utility installed on the client side gathering all the information mentioned above

A component maintaining the profile of a

                            "normal" use of the system, sitting on a central server (either the web application itself or some other...

First page image
We are pleased to offer a download of this document free of charge.
Files available for download:
  • a representative PDF of the primary file (contains all the relevant information for most users)
  • the full document ZIP file containing the primary file, packaged metadata, and attachments (as appropriate)
To obtain the file, please enter the "captcha" below and click the Download button.
Avoid entering CAPTCHAs! Sign In or Create a Free Account.

Challenge image
  • Please enter letters and numbers only; no spaces.
  • Cannot read this one? Click the image.
  • Difficulty with captchas? Contact us with the URL of this page and we will email it to you.