A Closer Look at Intrusion Detection System for Web Applications

Intrusion Detection System (IDS) acts as a defensive tool to detect the security attacks on the web. IDS is a known methodology for detecting network-based attacks but is still immature in monitoring and identifying web-based application attacks. The objective of this research paper is to present a...

Full description

Bibliographic Details
Main Authors: Nancy Agarwal, Syed Zeeshan Hussain
Format: Article
Language:English
Published: Hindawi-Wiley 2018-01-01
Series:Security and Communication Networks
Online Access:http://dx.doi.org/10.1155/2018/9601357
id doaj-00331869b32040feb8ed872b8420f2b7
record_format Article
spelling doaj-00331869b32040feb8ed872b8420f2b72020-11-24T23:54:49ZengHindawi-WileySecurity and Communication Networks1939-01141939-01222018-01-01201810.1155/2018/96013579601357A Closer Look at Intrusion Detection System for Web ApplicationsNancy Agarwal0Syed Zeeshan Hussain1Department of Computer Science, Jamia Millia Islamia, New Delhi, IndiaDepartment of Computer Science, Jamia Millia Islamia, New Delhi, IndiaIntrusion Detection System (IDS) acts as a defensive tool to detect the security attacks on the web. IDS is a known methodology for detecting network-based attacks but is still immature in monitoring and identifying web-based application attacks. The objective of this research paper is to present a design methodology for efficient IDS with respect to web applications. In this paper, we present several specific aspects which make it challenging for an IDS to monitor and detect web attacks. The article also provides a comprehensive overview of the existing detection systems exclusively designed to observe web traffic. Furthermore, we identify various dimensions for comparing the IDS from different perspectives based on their design and functionalities. We also propose a conceptual framework of a web IDS with a prevention mechanism to offer systematic guidance for the implementation of the system. We compare its features with five existing detection systems, namely, AppSensor, PHPIDS, ModSecurity, Shadow Daemon, and AQTRONIX WebKnight. This paper will highly facilitate the interest groups with the cutting-edge information to understand the stronger and weaker sections of the domain and provide a firm foundation for developing an intelligent and efficient system.http://dx.doi.org/10.1155/2018/9601357
collection DOAJ
language English
format Article
sources DOAJ
author Nancy Agarwal
Syed Zeeshan Hussain
spellingShingle Nancy Agarwal
Syed Zeeshan Hussain
A Closer Look at Intrusion Detection System for Web Applications
Security and Communication Networks
author_facet Nancy Agarwal
Syed Zeeshan Hussain
author_sort Nancy Agarwal
title A Closer Look at Intrusion Detection System for Web Applications
title_short A Closer Look at Intrusion Detection System for Web Applications
title_full A Closer Look at Intrusion Detection System for Web Applications
title_fullStr A Closer Look at Intrusion Detection System for Web Applications
title_full_unstemmed A Closer Look at Intrusion Detection System for Web Applications
title_sort closer look at intrusion detection system for web applications
publisher Hindawi-Wiley
series Security and Communication Networks
issn 1939-0114
1939-0122
publishDate 2018-01-01
description Intrusion Detection System (IDS) acts as a defensive tool to detect the security attacks on the web. IDS is a known methodology for detecting network-based attacks but is still immature in monitoring and identifying web-based application attacks. The objective of this research paper is to present a design methodology for efficient IDS with respect to web applications. In this paper, we present several specific aspects which make it challenging for an IDS to monitor and detect web attacks. The article also provides a comprehensive overview of the existing detection systems exclusively designed to observe web traffic. Furthermore, we identify various dimensions for comparing the IDS from different perspectives based on their design and functionalities. We also propose a conceptual framework of a web IDS with a prevention mechanism to offer systematic guidance for the implementation of the system. We compare its features with five existing detection systems, namely, AppSensor, PHPIDS, ModSecurity, Shadow Daemon, and AQTRONIX WebKnight. This paper will highly facilitate the interest groups with the cutting-edge information to understand the stronger and weaker sections of the domain and provide a firm foundation for developing an intelligent and efficient system.
url http://dx.doi.org/10.1155/2018/9601357
work_keys_str_mv AT nancyagarwal acloserlookatintrusiondetectionsystemforwebapplications
AT syedzeeshanhussain acloserlookatintrusiondetectionsystemforwebapplications
AT nancyagarwal closerlookatintrusiondetectionsystemforwebapplications
AT syedzeeshanhussain closerlookatintrusiondetectionsystemforwebapplications
_version_ 1725464675403956224