Back to Search
Start Over
Evaluating the web‐application resiliency to business‐layer DoS attacks.
- Source :
- ETRI Journal; Jun2020, Vol. 42 Issue 3, p433-445, 13p
- Publication Year :
- 2020
-
Abstract
- A denial‐of‐service (DoS) attack is a serious attack that targets web applications. According to Imperva, DoS attacks in the application layer comprise 60% of all the DoS attacks. Nowadays, attacks have grown into application‐ and business‐layer attacks, and vulnerability‐analysis tools are unable to detect business‐layer vulnerabilities (logic‐related vulnerabilities). This paper presents the business‐layer dynamic application security tester (BLDAST) as a dynamic, black‐box vulnerability‐analysis approach to identify the business‐logic vulnerabilities of a web application against DoS attacks. BLDAST evaluates the resiliency of web applications by detecting vulnerable business processes. The evaluation of six widely used web applications shows that BLDAST can detect the vulnerabilities with 100% accuracy. BLDAST detected 30 vulnerabilities in the selected web applications; more than half of the detected vulnerabilities were new and unknown. Furthermore, the precision of BLDAST for detecting the business processes is shown to be 94%, while the generated user navigation graph is improved by 62.8% because of the detection of similar web pages. [ABSTRACT FROM AUTHOR]
- Subjects :
- DENIAL of service attacks
WEB-based user interfaces
WEBSITES
Subjects
Details
- Language :
- English
- ISSN :
- 12256463
- Volume :
- 42
- Issue :
- 3
- Database :
- Supplemental Index
- Journal :
- ETRI Journal
- Publication Type :
- Academic Journal
- Accession number :
- 143594299
- Full Text :
- https://doi.org/10.4218/etrij.2019-0164