• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. TokDoc: A self-healing web application firewall
 
  • Details
  • Full
Options
2010
Conference Paper
Title

TokDoc: A self-healing web application firewall

Abstract
The growing amount of web-based attacks poses a severe threat to the security of web applications. Signature-based detection techniques increasingly fail to cope with the variety and complexity of novel attack instances. As a remedy, we introduce a protocol-aware reverse HTTP proxy TokDoc (the token doctor), which intercepts requests and decides on a per-token basis whether a token requires automatic "healing". In particular, we propose an intelligent mangling technique, which, based on the decision of previously trained anomaly detectors, replaces suspicious parts in requests by benign data the system has seen in the past. Evaluation of our system in terms of accuracy is performed on two real-world data sets and a large variety of recent attacks. In comparison to state-of-the-art anomaly detectors, TokDoc is not only capable of detecting most attacks, but also significantly outperforms the other methods in terms of false positives. Runtime measurements show that our im plementation can be deployed as an inline intrusion prevention system.
Author(s)
Krueger, T.
Gehl, C.
Rieck, K.
Laskov, P.
Mainwork
Proceedings of the 25th Annual ACM Symposium on Applied Computing 2010. CD-ROM  
Conference
Annual ACM Symposium on Applied Computing 2010  
DOI
10.1145/1774088.1774480
Language
English
FIRST
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024