Web Application Firewall Using Proxy and Security Information and Event Management (SIEM) for OWASP Cyber Attack Detection


연구 분야: Safety



학회: 2023 IEEE International Conference on Internet of Things and Intelligence Systems (IoTaIS)


초록

Web applications face increasing security threats, with a 210% rise in attacks in 2022 compared to 2020, including 172 daily attacks per website and 2,306 weekly bot accesses. The most prevalent vulnerabilities are Cross-Site Scripting (XSS) affecting 1 million websites and SQL injection impacting 332,000 pages. To address these issues, a WordPress plugin is designed, integrating Security Information and Event Management (SIEM) and a proxy-based Web Application Firewall (WAF). The proxy based WAF enhances website security by detecting and blocking malicious requests based on OWASP rules, while SIEM collects and simplifies security data from various sources. This system effectively identifies XSS at 100%, SQL Injection at 97%, and Local File Inclusion (LFI) at 74% according to OWASP standards.


Author Profile
Tia Rahmawati

School of Electrical Engineering Telkom University Bandung Indonesia

Indonesia
Author Profile
Rama Wijaya Shiddiq

School of Electrical Engineering Telkom University Bandung Indonesia

Indonesia
Author Profile
Mochamad Rizal Sumpena

School of Electrical Engineering Telkom University Bandung Indonesia

Indonesia

📄 논문 정보

발행 연도 2023년
인용수 5
출판 국가 Indonesia
사이트 IEEE
좋아요 수 0

연관 논문 목록 (16건)