{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T03:42:50Z","timestamp":1760240570372,"version":"build-2065373602"},"reference-count":44,"publisher":"MDPI AG","issue":"8","license":[{"start":{"date-parts":[[2019,7,29]],"date-time":"2019-07-29T00:00:00Z","timestamp":1564358400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Algorithms"],"abstract":"<jats:p>A novel approach to defacement detection is proposed in this paper, addressing explicitly the possible presence of a passive adversary. Defacement detection is an important security measure for Web Sites and Applications, aimed at avoiding unwanted modifications that would result in significant reputational damage. As in many other anomaly detection contexts, the algorithm used to identify possible defacements is obtained via an Adversarial Machine Learning process. We consider an exploratory setting, where the adversary can observe the detector\u2019s alarm-generating behaviour, with the purpose of devising and injecting defacements that will pass undetected. It is then necessary to make to learning process unpredictable, so that the adversary will be unable to replicate it and predict the classifier\u2019s behaviour. We achieve this goal by introducing a secret key\u2014a key that our adversary does not know. The key will influence the learning process in a number of different ways, that are precisely defined in this paper. This includes the subset of examples and features that are actually used, the time of learning and testing, as well as the learning algorithm\u2019s hyper-parameters. This learning methodology is successfully applied in this context, by using the system with both real and artificially modified Web sites. A year-long experimentation is also described, referred to the monitoring of the new Web Site of a major manufacturing company.<\/jats:p>","DOI":"10.3390\/a12080150","type":"journal-article","created":{"date-parts":[[2019,7,29]],"date-time":"2019-07-29T11:20:18Z","timestamp":1564399218000},"page":"150","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Defacement Detection with Passive Adversaries"],"prefix":"10.3390","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2567-336X","authenticated-orcid":false,"given":"Francesco","family":"Bergadano","sequence":"first","affiliation":[{"name":"Dipartimento di Informatica, Universit\u00e0 di Torino, Corso Svizzera 185, 10149 Torino, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fabio","family":"Carretto","sequence":"additional","affiliation":[{"name":"Certimeter Group, Corso Svizzera 185, 10149 Torino, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5639-5062","authenticated-orcid":false,"given":"Fabio","family":"Cogno","sequence":"additional","affiliation":[{"name":"Certimeter Group, Corso Svizzera 185, 10149 Torino, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dario","family":"Ragno","sequence":"additional","affiliation":[{"name":"Certimeter Group, Corso Svizzera 185, 10149 Torino, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2019,7,29]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"10:1","DOI":"10.1145\/1852096.1852098","article-title":"A Framework for Large-Scale Detection of Web Site Defacements","volume":"10","author":"Bartoli","year":"2010","journal-title":"ACM Trans. Internet Technol."},{"key":"ref_2","unstructured":"Borgolte, K., Kruegel, C., and Vigna, G. (2015, January 12\u201314). Meerkat: Detecting Website Defacements through Image-based Object Recognition. Proceedings of the 24th USENIX Security Symposium, Washington, DC, USA."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Borgolte, K., Kruegel, C., and Vigna, G. (2014, January 7\u201311). Relevant Change Detection: Framework for the Precise Extraction of Modified and Novel Web-based Content as a Filtering Technique for Analysis Engines. Proceedings of the 23rd International Conference on World Wide Web Conference (WWW) (IW3C2), Seoul, Korea.","DOI":"10.1145\/2567948.2578039"},{"key":"ref_4","unstructured":"Cooks, A., and Olivier, M. (July, January 30). Curtailing web defacement using a read-only strategy. Proceedings of the 4th Annual Information Security South Africa Conference, Midrand, South Africa."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Davanzo, G., Medvet, E., and Bartoli, A. (2008). A Comparative Study of Anomaly Detection Techniques in Web Site Defacement Detection. Proceedings of the Ifip Tc 11 23rd International Information Security Conference (SEC 2008), Springer.","DOI":"10.1007\/978-0-387-09699-5_50"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"12521","DOI":"10.1016\/j.eswa.2011.04.038","article-title":"Anomaly detection techniques for a web defacement monitoring service","volume":"38","author":"Davanzo","year":"2011","journal-title":"Expert Syst. Appl."},{"key":"ref_7","first-page":"77","article-title":"A conceptual approach to detect web defacement through Artificial Intelligence","volume":"3","author":"Enaw","year":"2014","journal-title":"Int. J. Adv. Comput. Technol."},{"key":"ref_8","first-page":"252","article-title":"Implementation of an efficient web defacement detection technique and spotting exact defacement location using diff algorithm","volume":"2","author":"Kanti","year":"2012","journal-title":"Int. Emerg. Technol. Adv. Eng."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Liao, X., Yuan, K., Wang, X., Pei, Z., Yang, H., Chen, J., Duan, H., Du, K., Alowaisheq, E., and Alrwais, S. (2016, January 22\u201326). Seeking Nonsense, Looking for Trouble: Efficient Promotional-Infection Detection through Semantic Inconsistency Search. Proceedings of the IEEE Symposium on Security and Privacy, San Jose, CA, USA.","DOI":"10.1109\/SP.2016.48"},{"key":"ref_10","first-page":"134","article-title":"Implementation of Web Defacement Detection Technique","volume":"6","author":"Verma","year":"2015","journal-title":"Int. J. Innov. Eng. Technol."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Viswanathan, N., and Mishra, A. (2016). Dynamic Monitoring of Website Content and Alerting Defacement Using Trusted Platform Module. Emerging Research in Computing, Information, Communication and Applications, Springer.","DOI":"10.1007\/978-981-10-0287-8_11"},{"key":"ref_12","unstructured":"Kumar, C. (2019, July 27). 7 Website Defacement Monitoring Tools for Better Security. Available online: https:\/\/geekflare.com\/website-defacement-monitoring\/."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"52","DOI":"10.1109\/MIC.2009.91","article-title":"The Reaction Time to Web Site Defacements","volume":"13","author":"Bartoli","year":"2009","journal-title":"IEEE Internet Comput."},{"key":"ref_14","unstructured":"Chee, W.O. (2016, January 22). Web Defacements and Data Leakages\u2014Twin Towers website threats. Proceedings of the RSA Conference, Singapore."},{"key":"ref_15","unstructured":"Zone-H.org (2019, July 27). Statistics Report 2008\u20132016. Available online: http:\/\/www.zone-h.org\/stats\/ymd."},{"key":"ref_16","unstructured":"(2019, July 27). Zone-H.org. Available online: http:\/\/www.zone-h.org\/."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Maggi, F., Balduzzi, M., Flores, R., Gu, L., and Ciancaglini, V. (2018, January 4). Investigating Web Defacement Campaigns at Large. Proceedings of the 2018 on Asia Conference on Computer and Communications Security (AsiaCCS 2018), Incheon, Korea.","DOI":"10.1145\/3196494.3196542"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Biggio, B., Fumera, G., and Roli, F. (2008, January 4). Adversarial Pattern Classification Using Multiple Classifiers and Randomization. Proceedings of the 12th Joint IAPR International Workshop on Structural and Syntactic Pattern Recognition, Orlando, FL, USA.","DOI":"10.1007\/978-3-540-89689-0_54"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Chen, Y., Wang, W., and Zhang, X. (2018, January 3\u20136). Randomizing SVM Against Adversarial Attacks Under Uncertainty. Proceedings of the Pacific-Asia Conference on Knowledge Discovery and Data Mining (PAKDD), Melbourne, Australia.","DOI":"10.1007\/978-3-319-93040-4_44"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"2466","DOI":"10.1109\/TNNLS.2016.2593488","article-title":"Randomized Prediction Games for Adversarial Machine Learning","volume":"28","author":"Biggio","year":"2017","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Barreno, M., Nelson, B., Sears, R., Joseph, A.D., and Tygar, J.D. (2006, January 21\u201324). Can Machine Learning be Secure?. Proceedings of the 2006 ACM Symposium on Information, Computer and Communi-cations Security (AsiaCCS), Taipei, Taiwan.","DOI":"10.1145\/1128817.1128824"},{"key":"ref_22","first-page":"12","article-title":"Survey on Keyed IDS and Key Recovery Attacks","volume":"4","author":"Lomte","year":"2015","journal-title":"Int. J. Sci. Res."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Mrdovic, R.S., and Drazenovic, B. (2010, January 8\u20139). KIDS\u2014Keyed Intrusion Detection System. Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA), Bonn, Germany.","DOI":"10.1007\/978-3-642-14215-4_10"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"864","DOI":"10.1016\/j.comnet.2008.11.011","article-title":"McPAD: A Multiple Classifier System for Accurate Payload-based Anomaly Detection","volume":"5","author":"Perdisci","year":"2009","journal-title":"Comput. Netw."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Wang, K., Parekh, J., and Stolfo, S. (2006, January 20\u201322). Anagram: A Content Anomaly Detector Resistant to Mimicry Attack. Proceedings of the 9th International Conference on Recent Advances in Intrusion Detection, Hamburg, Germany.","DOI":"10.1007\/11856214_12"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Bergadano, F., Carretto, F., Cogno, F., and Ragno, D. (2017, January 27\u201330). Defacement Response via Keyed Learning. Proceedings of the 8th IEEE IISA Conference International Conference on Information, Intelligence, Systems & Applications (IISA), Larnaca, Cyprus.","DOI":"10.1109\/IISA.2017.8316359"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"367","DOI":"10.1145\/581271.581272","article-title":"User Authentication through Keystroke Dynamics","volume":"5","author":"Bergadano","year":"2002","journal-title":"Acm Trans. Inf. Syst. Secur."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Anwar, S., Zain, J.M., Zolkipli, M.F., Inayat, Z., Khan, S., Anthony, B., and Chang, V. (2017). From Intrusion Detection to an Intrusion Response System: Fundamentals, Requirements, and Future Directions. Algorithms, 10.","DOI":"10.3390\/a10020039"},{"key":"ref_29","unstructured":"Munaiah, N., Meneely, A., Wilson, R., and Short, B. (2016). Are Intrusion Detection Studies Evaluated Consistently? A Systematic Literature Review, University of Rochester. Technical Report."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1186\/s13635-018-0074-y","article-title":"Foundations and applications of artificial Intelligence for zero-day and multi-step attack detection","volume":"2018","author":"Parrend","year":"2018","journal-title":"Eurasip J. Inf. Secur."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"807","DOI":"10.1137\/0222052","article-title":"Learning in the presence of malicious errors","volume":"22","author":"Kearns","year":"1993","journal-title":"Siam Comput."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Huang, L., Joseph, A.D., Nelson, B., Rubinstein, B., and Tygar, J.D. (2011, January 21). Adversarial Machine Learning. Proceedings of the ACM Workshop on AI and Security, AISec\u201911, Chicago, IL, USA.","DOI":"10.1145\/2046684.2046692"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Lowd, D., and Meek, C. (2005, January 21\u201324). Adversarial Learning. Proceedings of the 11th ACM SIGKDD international conference on Knowledge Discovery in Data Mining, Chicago, IL, USA.","DOI":"10.1145\/1081870.1081950"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"\u0160rndic, N., and Laskov, P. (2014, January 18\u201321). Practical Evasion of a Learning-Based Classifier: A Case Study. Proceedings of the IEEE Symposium on Security and Privacy, San Jose, CA, USA.","DOI":"10.1109\/SP.2014.20"},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"312","DOI":"10.1109\/TDSC.2013.39","article-title":"Key-Recovery Attacks on KIDS, a Keyed Anomaly Detection System","volume":"12","author":"Tapiador","year":"2015","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Aggarwal, C., Pei, J., and Zhang, B. (2006, January 20\u201323). On privacy preservation against adversarial data mining. Proceedings of the 12th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, Philadelphia, PA, USA.","DOI":"10.1145\/1150402.1150460"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Biggio, B., Corona, I., Maiorca, D., Nelson, B., \u0160rndic, N., Laskov, P., Giacinto, G., and Roli, F. (2013). Evasion Attacks against Machine Learning at Test Time. Machine Learning and Knowledge Discovery in Databases, European Conference, ECML PKDD, Prague, Czech Republic, 23\u201327 September 2013, Springer. Lecture Notes in Computer Science.","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"ref_38","first-page":"312","article-title":"KIDS: Keyed Anomaly Detection System","volume":"12","author":"Bendale","year":"2017","journal-title":"Int. J. Adv. Eng. Res. Dev."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Bergadano, F., and Giordana, A. (1988, January 12\u201314). A Knowledge Intensive Approach to Concept Induction. Proceedings of the Fifth International Conference on Machine Learning, Ann Arbor, MI, USA.","DOI":"10.1016\/B978-0-934613-64-4.50037-2"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Arkkom, J., Carrara, E., Lindholm, F., Naslund, M., and Norman, K. (2004). MIKEY: Multimedia Internet KEYing, IETF. IETF RFC 3820.","DOI":"10.17487\/rfc3830"},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Chen, L. (2009). Recommendation for Key Derivation Using Pseudorandom Functions.","DOI":"10.6028\/NIST.SP.800-108"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Dierks, T., and Rescorla, E. (2008). The Transport Layer Security (TLS) Protocol Version 1.2, IETF. IETF RFC 5246.","DOI":"10.17487\/rfc5246"},{"key":"ref_43","unstructured":"Xiao, H., Brown, B.B.G., Fumera, G., Eck-ert, C., and Roli, F. (2015, January 6\u201311). Is feature selection secure against training data poisoning?. Proceedings of the 32nd International Conference on Machine Learning (ICML\u201915), Lille, France."},{"key":"ref_44","unstructured":"Hancock, T. (1989). On the Difficulty of Finding Small Consistent Decision Trees, Unpublished manuscript."}],"container-title":["Algorithms"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-4893\/12\/8\/150\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T13:10:50Z","timestamp":1760188250000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-4893\/12\/8\/150"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,7,29]]},"references-count":44,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2019,8]]}},"alternative-id":["a12080150"],"URL":"https:\/\/doi.org\/10.3390\/a12080150","relation":{},"ISSN":["1999-4893"],"issn-type":[{"type":"electronic","value":"1999-4893"}],"subject":[],"published":{"date-parts":[[2019,7,29]]}}}