Summary
These summaries highlight various aspects of improving web application security, focusing on trends, tools, and technologies used for protection. Summary 1 discusses the alarming increase in web application vulnerabilities, with a significant rise in attacks reported in 2022. It emphasizes common vulnerabilities such as Cross-Site Scripting (XSS) and SQL injection and introduces a WordPress plugin that integrates Security Information and Event Management (SIEM) with a proxy-based Web Application Firewall (WAF) to block malicious requests effectively. Summary 2 addresses the rise of data leakage incidents in Indonesia, including a notable breach in 2021. This summary describes the development of a WAF using ModSecurity and OWASP Core Rule Set, achieving high detection rates for SQL Injection and XSS attacks. The focus is on using UML for system analysis and testing with platforms like DVWA and WordPress, emphasizing real-time attack logs and WAF integration to bolster cybersecurity. Summary 3 explores the use of machine learning to automate WAF configuration, contrasting it with traditional rule-based firewalls. The method leverages anomaly detection for identifying normal request patterns and creating whitelists, though it highlights the need for labeled datasets. It discusses automatic dataset generation and presents test results, showing improved performance over classic firewalls, particularly with WordPress implementations. Overall, the summaries underscore the importance of evolving security measures and technologies in response to increasing web application vulnerabilities and attacks.
Data leakage incidents, including the BPJS Health breach in Indonesia, have risen. A Web Application Firewall using ModSecurity and OWASP Core Rule Set achieved high detection rates against SQL Injection and XSS attacks.
Published By:
Muhammad Annas - undefined
2024
Cited By:
0
Automating Web Application Firewall configuration with machine learning simplifies setup and improves protection. Anomaly detection aids whitelist creation, but may require labeled datasets for accuracy.
Published By:
Alexandr Kozhevnikov - undefined
2024
Cited By:
0
Web applications are increasingly vulnerable with attacks rising by 210% in 2022 compared to 2020. Common vulnerabilities include XSS, SQL injection, and a WordPress plugin offers protection based on OWASP rules.
Published By:
Tia Rahmawati - International Conference on Internet of Things and Intelligence System
2023
Cited By:
1