{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,14]],"date-time":"2026-03-14T02:59:39Z","timestamp":1773457179618,"version":"3.50.1"},"reference-count":30,"publisher":"Emerald","issue":"5","license":[{"start":{"date-parts":[[2011,11,22]],"date-time":"2011-11-22T00:00:00Z","timestamp":1321920000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011,11,22]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-heading\">Purpose<\/jats:title><jats:p>The purpose of this paper is to introduce a new tool which detects, prevents and records common web attacks that mainly result in web applications information leaking using pattern recognition. It is a cross\u2010platform application, namely, it is not OS\u2010dependent or web server dependent. It offers a flexible attacks search engine, which scans http requests and responses during a webpage serving without affecting the web server performance.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title><jats:p>The paper starts with a study of the most known web vulnerabilities and the way they can be exploited. Then, it focuses on those web attacks based on input validation, which are the ones the new tool detects through pattern recognition. This tool acts as a proxy server having a simple GUI for administration purposes. Patterns can be detected in both http requests and responses in an extensible and manageable way.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Findings<\/jats:title><jats:p>The new tool was compared to dotDefender, a commercial web application firewall, and ModSecurity, a widely used open source application firewall, using over 200 attack patterns. The new tool had satisfying results for every attack category examined having a high percentage of success. Results for stored XSS could not be achieved since the other tools are not able to search and detect them in http responses. The fact that the new tool is very extensible, it makes it possible for future work to be done.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title><jats:p>This paper introduces a new web server plug\u2010in, which has some advanced web application firewall features with a flexible attacks search engine which scans http requests and responses. By scanning http responses, attacks such as stored XSS can be detected, a feature that cannot be found on other web application firewalls.<\/jats:p><\/jats:sec>","DOI":"10.1108\/09685221111188584","type":"journal-article","created":{"date-parts":[[2011,11,26]],"date-time":"2011-11-26T07:06:13Z","timestamp":1322291173000},"page":"280-299","source":"Crossref","is-referenced-by-count":8,"title":["An advanced web attack detection and prevention tool"],"prefix":"10.1108","volume":"19","author":[{"given":"Helen","family":"Kapodistria","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sarandis","family":"Mitropoulos","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christos","family":"Douligeris","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"key":"key2022012119582203700_b1","unstructured":"Acunetix (2010), available at: www.acunetix.com\/ (accessed October 2010)."},{"key":"key2022012119582203700_b3","doi-asserted-by":"crossref","unstructured":"Bertino, E., Martino, L., Paci, F. and Squicciarini, A. (2010), Security for Web Services and Service\u2010oriented Architectures, Springer, Berlin.","DOI":"10.1007\/978-3-540-87742-4"},{"key":"key2022012119582203700_b4","unstructured":"Comer, D. (2003), Hands\u2010on Networking with Internet Applications, Prentice\u2010Hall, Upper Saddle River, NJ."},{"key":"key2022012119582203700_b5","unstructured":"Di Lucca, G.A., Fasolino, A.R., Mastoianni, M. and Tramontana, P. (2004), \u201cIdentifying cross site scripting vulnerabilities in web applications\u201d, 6th IEEE International Workshop on Website Evolution (WSE'04), Chicago, IL, pp. 71\u201080."},{"key":"key2022012119582203700_b6","unstructured":"dotDefender (2010), available at: www.applicure.com (accessed October 2010)."},{"key":"key2022012119582203700_b7","unstructured":"Fielding, R., Gettys, J., Mogul, J., Frystyk, H., Masinter, L., Leach, P. and Berners\u2010Lee, T. (2009), Hypertext transfer protocol specification \u2013 HTTP 1.1."},{"key":"key2022012119582203700_b8","doi-asserted-by":"crossref","unstructured":"Fong, E. and Okun, V. (2007), \u201cWeb vulnerability scanners: definitions and functions\u201d, Proceedings of the 40th Annual Hawaii International Conference on System Sciences (HICSS'07), IEEE, New York, NY.","DOI":"10.1109\/HICSS.2007.611"},{"key":"key2022012119582203700_b9","unstructured":"Gauci, S. and Henrique, W.G. (2010), \u201cWeb application firewalls: what the vendors do not want you to know\u201d, paper presented at OWASP AppSecEU09 Poland, OWASP: available at: www.owasp.org\/(\/0\/(\/Appseceu09\u2010Web_Application_Firewalls.pdf (accessed January 2010)."},{"key":"key2022012119582203700_b11","doi-asserted-by":"crossref","unstructured":"Johns, M., Beyerlein, C., Giesecke, R. and Posegga, J. (2010), \u201cSecure code generation for web applications\u201d, 2nd International Symposium on Engineering Secure Software and Systems (ESSoS'10), LNCS 5965, Springer, Berlin, pp. 96\u2010113.","DOI":"10.1007\/978-3-642-11747-3_8"},{"key":"key2022012119582203700_b14","unstructured":"ModSecurity (2010), available at: www.modsecurity.org\/ (accessed October 2010)."},{"key":"key2022012119582203700_b17","unstructured":"OWASP (2007), \u201cTop 10 project 2007\u201d, OWASP: available at: www.owasp.org\/index.php\/Top_10_2007 (accessed December 2008)."},{"key":"key2022012119582203700_b16","unstructured":"OWASP (2010a), \u201cOWASP enterprise security API\u201d, available at: www.owasp.org\/index.php\/Category:OWASP_Enterprise_Security_API (accessed October 2010)."},{"key":"key2022012119582203700_b18","unstructured":"OWASP (2010b), \u201cOWASP projects\u201d, OWASP: available at: www.owasp.org\/index.php\/Category:OWASP_Project."},{"key":"key2022012119582203700_b19","unstructured":"Paros (2010), available at: www.parosproxy.org (accessed October 2010)."},{"key":"key2022012119582203700_b20","unstructured":"PCI Standards (2008), \u201cInformation supplement: application reviews and web application firewalls clarified\u201d, PCI Data Security Standard (PCI DSS), October, Requirement 6.6."},{"key":"key2022012119582203700_b21","doi-asserted-by":"crossref","unstructured":"Schultz, E. and Ray, E. (2007), \u201cThe future of intrusion prevention\u201d, Computer Fraud & Security, No. 8, pp. 11\u201013.","DOI":"10.1016\/S1361-3723(07)70103-3"},{"key":"key2022012119582203700_b22","unstructured":"Shema, M. (2010), Seven Deadliest Web Application Attacks, Syngress, Shah Alam."},{"key":"key2022012119582203700_b23","unstructured":"Shklar, L. and Rosen, R. (2003), Web Application Architecture, Principles, Protocols and Practices, Wiley, New York, NY."},{"key":"key2022012119582203700_b25","doi-asserted-by":"crossref","unstructured":"Wassermann, G. and Su, Z. (2007), \u201cSound and precise analysis of web applications for injection vulnerabilities\u201d, Proceedings of the 2007 PLDI Conference, Vol. 42 No. 6, pp. 32\u201041.","DOI":"10.1145\/1273442.1250739"},{"key":"key2022012119582203700_b26","doi-asserted-by":"crossref","unstructured":"Watson, D. (2007), \u201cWeb application attacks\u201d, Network Security, No. 10, pp. 10\u201013.","DOI":"10.1016\/S1353-4858(07)70094-6"},{"key":"key2022012119582203700_b28","unstructured":"Web Application Security Consortium (2010a), \u201cProjects\u201d, paper presented at Web Application Security Consortium, available at: www.webappsec.org\/projects\/ (accessed December 2010)."},{"key":"key2022012119582203700_b27","unstructured":"Web Application Security Consortium (2010b), \u201cWeb security glossary\u201d, paper presented at Web Application Security Consortium, available at: www.webappsec.org\/projects\/glossary\/ (accessed December 2010)."},{"key":"key2022012119582203700_b29","unstructured":"WebScarab (2010), OWASP, available at: www.owasp.org\/index.php\/Category:OWASP_WebScarab_Project (accessed October 2010)."},{"key":"key2022012119582203700_frd1","doi-asserted-by":"crossref","unstructured":"Armstrong, N. (2007), \u201cClient attacks, network infiltration with client\u2010side attacks\u201d, Network Security, No. 9, pp. 8\u201010.","DOI":"10.1016\/S1353-4858(07)70081-8"},{"key":"key2022012119582203700_frd2","unstructured":"Hoglund, G. and McGraw, G. (2004), Exploiting Software: How to Break Code, Addison\u2010Wesley, New York, NY."},{"key":"key2022012119582203700_frd3","unstructured":"Matt, B. (2008), \u201cHow attackers attack programs, and how to write more secure programs\u201d, University of California at Davis, available at: www.nob.cs.ucdavis.edu\/\u223cbishop\/secprog\/sans2002\/index.html (accessed December 2008)."},{"key":"key2022012119582203700_frd4","unstructured":"Microsoft Developer Network (2009), \u201cPatterns & practices, design guidelines for secure web applications\u201d, Microsoft Developer Network (MSDN), available at: www.msdn.microsoft.com\/en\u2010us\/library\/aa302420.aspx (accessed October 2009)."},{"key":"key2022012119582203700_frd5","unstructured":"Mookhey, K.K. and Burghate, N. (2008), \u201cDetection of SQL injection and cross\u2010site scripting attacks\u201d, SecurityFocus, available at: www.securityfocus.com\/infocus\/1768 (accessed December 2008)."},{"key":"key2022012119582203700_frd6","doi-asserted-by":"crossref","unstructured":"Stuttard, D. and Pinto, M. (2008), The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws, Wiley, New York, NY.","DOI":"10.1016\/S1353-4858(08)70112-0"},{"key":"key2022012119582203700_frd7","unstructured":"WhiteHat Security (2009), WhiteHat Website Security Statistic Report, Spring 2009, 7th ed., WhiteHat Security, available at: www.whitehatsec.com\/home\/assets\/WPstats_spring09_7th.pdf (accessed September 2009)."}],"container-title":["Information Management &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/09685221111188584","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/09685221111188584\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/09685221111188584\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T00:09:23Z","timestamp":1753402163000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/19\/5\/280-299\/181751"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,11,22]]},"references-count":30,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2011,11,22]]}},"alternative-id":["10.1108\/09685221111188584"],"URL":"https:\/\/doi.org\/10.1108\/09685221111188584","relation":{},"ISSN":["0968-5227"],"issn-type":[{"value":"0968-5227","type":"print"}],"subject":[],"published":{"date-parts":[[2011,11,22]]}}}