Logo del repository
  1. Home
 
Opzioni

A Framework for Large-Scale Detection of Web Site Defacements

BARTOLI, Alberto
•
DAVANZO, GIORGIO
•
MEDVET, Eric
2010
  • journal article

Periodico
ACM TRANSACTIONS ON INTERNET TECHNOLOGY
Abstract
Web site defacement, the process of introducing unauthorized modifications to a web site, is a very common form of attack. In this paper we describe and evaluate experimentally a framework that may constitute the basis for a defacement detection service capable of monitoring thousands of remote web sites systematically and automatically. In our framework an organization may join the service by simply providing the URLs of the resources to be monitored along with the contact point of an administrator. The monitored organization may thus take advantage of the service with just a few mouse clicks, without installing any software locally nor changing its own daily operational processes. Our approach is based on anomaly detection and allows monitoring the integrity of many remote web resources automatically while remaining fully decoupled from them, in particular, without requiring any prior knowledge about those resources. We evaluated our approach over a selection of dynamic resources and a set of publicly available defacements. The results are very satisfactory: all attacks are detected while keeping false positives to a minimum. We also assessed performance and scalability of our proposal and we found that it may indeed constitute the basis for actually deploying the proposed service on a large-scale.
DOI
10.1145/1852096.1852098
WOS
WOS:000284516700002
Archivio
http://hdl.handle.net/11368/2299899
info:eu-repo/semantics/altIdentifier/scopus/2-s2.0-78049325551
Diritti
metadata only access
Soggetti
  • Intrusion detection

  • monitoring service

  • Web site defacement

  • experimental evaluati...

Web of Science© citazioni
17
Data di acquisizione
Mar 28, 2024
Visualizzazioni
1
Data di acquisizione
Apr 19, 2024
Vedi dettagli
google-scholar
Get Involved!
  • Source Code
  • Documentation
  • Slack Channel
Make it your own

DSpace-CRIS can be extensively configured to meet your needs. Decide which information need to be collected and available with fine-grained security. Start updating the theme to match your nstitution's web identity.

Need professional help?

The original creators of DSpace-CRIS at 4Science can take your project to the next level, get in touch!

Realizzato con Software DSpace-CRIS - Estensione mantenuta e ottimizzata da 4Science

  • Impostazioni dei cookie
  • Informativa sulla privacy
  • Accordo con l'utente finale
  • Invia il tuo Feedback