Comparativa de la eficacia de herramientas WAF y RASP frente a ataques
Autor:
Sureda Riera, Tomás
Fecha:
21/01/2017Palabra clave:
Tipo de Ítem:
masterThesisResumen:
En este trabajo de fin de máster, se ha evaluado la eficacia de diferentes soluciones WAF y RASP protegiendo a aplicaciones web frente a diversos ataques. Se han simulado diversos escenarios, interponiendo las soluciones a evaluar entre la aplicación a proteger – simulada por dos bancos de pruebas – y la máquina atacante.
Los resultados producidos por las distintas soluciones, se han analizado mediante diversas métricas y se han ordenado mediante la puntuación F-Score.
Del análisis de los resultados obtenidos se concluye la superioridad de las soluciones RASP frente a WAF en la mayoría de los índices, así como la práctica inexistencia de diferencias en la puntuación obtenida en las distintas métricas, de las dos soluciones WAF.
La solución que mejores resultados ha obtenido es Contrast.
Descripción:
In this Master’s degree final project, the effectiveness of different WAF and RASP tools has been evaluated, protecting web applications against various attacks. Several scenarios have been simulated, interposing the protection tool to be assessed between the application to be protected – simulated by two benchmarks – and the attacking machine.
The results obtained from the different protection tools have been analyzed using different metrics and have been sorted by the F-Score index.
From the analysis of the obtained results, the superiority in most indexes of RASP against WAF tools is concluded, as well as the practical absence of differences in the score obtained in the different metrics of the two WAF tools.
The tool that obtained the best results is Contrast.
Ficheros en el ítem
Este ítem aparece en la(s) siguiente(s) colección(es)
Estadísticas de uso
Año |
2012 |
2013 |
2014 |
2015 |
2016 |
2017 |
2018 |
2019 |
2020 |
2021 |
2022 |
2023 |
2024 |
Vistas |
0 |
0 |
0 |
0 |
0 |
0 |
219 |
132 |
203 |
148 |
215 |
171 |
334 |
Descargas |
0 |
0 |
0 |
0 |
0 |
0 |
813 |
986 |
1191 |
946 |
427 |
422 |
434 |
Ítems relacionados
Mostrando ítems relacionados por Título, autor o materia.
-
Prevention and fighting against web attacks through anomaly detection technology. A systematic review
Sureda Riera, Tomás; Bermejo Higuera, Juan Ramón ; Bermejo-Higuera, Javier ; Martínez Herraiz, José-Javier; Sicilia, Juan Antonio (Sustainability (Switzerland), 01/06/2020)Numerous techniques have been developed in order to prevent attacks on web servers. Anomaly detection techniques are based on models of normal user and application behavior, interpreting deviations from the established ... -
Combinatorial method with static analysis for source code security in web applications
Bermejo Higuera, Juan Ramón ; Bermejo-Higuera, Javier ; Sicilia, Juan Antonio ; Sureda Riera, Tomás; Argyros, Christopher I.; Magreñán, Á. Alberto (Tech Science Press, 2021)Security weaknesses in web applications deployed in cloud architectures can seriously affect its data confidentiality and integrity. The construction of the procedure utilized in the static analysis tools of source code ... -
A new multi-label dataset for Web attacks CAPEC classification using machine learning techniques
Sureda Riera, Tomás; Bermejo Higuera, Juan Ramón ; Bermejo-Higuera, Javier ; Martínez Herraiz, José-Javier; Sicilia, Juan Antonio (Computers & Security, 2022)Context: There are many datasets for training and evaluating models to detect web attacks, labeling each request as normal or attack. Web attack protection tools must provide additional information on the type of attack ...