In-Application Defense Against Evasive Web Scans through Behavioral Analysis

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Ousat, Behzad, Shariatnasab, Mahshad, Schafir, Esteban, Chaharsooghi, Farhad Shirani, Kharraz, Amin
Format: Preprint
Publié: 2024
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866915055643131904
author Ousat, Behzad
Shariatnasab, Mahshad
Schafir, Esteban
Chaharsooghi, Farhad Shirani
Kharraz, Amin
author_facet Ousat, Behzad
Shariatnasab, Mahshad
Schafir, Esteban
Chaharsooghi, Farhad Shirani
Kharraz, Amin
contents Web traffic has evolved to include both human users and automated agents, ranging from benign web crawlers to adversarial scanners such as those capable of credential stuffing, command injection, and account hijacking at the web scale. The estimated financial costs of these adversarial activities are estimated to exceed tens of billions of dollars in 2023. In this work, we introduce WebGuard, a low-overhead in-application forensics engine, to enable robust identification and monitoring of automated web scanners, and help mitigate the associated security risks. WebGuard focuses on the following design criteria: (i) integration into web applications without any changes to the underlying software components or infrastructure, (ii) minimal communication overhead, (iii) capability for real-time detection, e.g., within hundreds of milliseconds, and (iv) attribution capability to identify new behavioral patterns and detect emerging agent categories. To this end, we have equipped WebGuard with multi-modal behavioral monitoring mechanisms, such as monitoring spatio-temporal data and browser events. We also design supervised and unsupervised learning architectures for real-time detection and offline attribution of human and automated agents, respectively. Information theoretic analysis and empirical evaluations are provided to show that multi-modal data analysis, as opposed to uni-modal analysis which relies solely on mouse movement dynamics, significantly improves time-to-detection and attribution accuracy. Various numerical evaluations using real-world data collected via WebGuard are provided achieving high accuracy in hundreds of milliseconds, with a communication overhead below 10 KB per second.
format Preprint
id arxiv_https___arxiv_org_abs_2412_07005
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle In-Application Defense Against Evasive Web Scans through Behavioral Analysis
Ousat, Behzad
Shariatnasab, Mahshad
Schafir, Esteban
Chaharsooghi, Farhad Shirani
Kharraz, Amin
Machine Learning
Cryptography and Security
Information Theory
Web traffic has evolved to include both human users and automated agents, ranging from benign web crawlers to adversarial scanners such as those capable of credential stuffing, command injection, and account hijacking at the web scale. The estimated financial costs of these adversarial activities are estimated to exceed tens of billions of dollars in 2023. In this work, we introduce WebGuard, a low-overhead in-application forensics engine, to enable robust identification and monitoring of automated web scanners, and help mitigate the associated security risks. WebGuard focuses on the following design criteria: (i) integration into web applications without any changes to the underlying software components or infrastructure, (ii) minimal communication overhead, (iii) capability for real-time detection, e.g., within hundreds of milliseconds, and (iv) attribution capability to identify new behavioral patterns and detect emerging agent categories. To this end, we have equipped WebGuard with multi-modal behavioral monitoring mechanisms, such as monitoring spatio-temporal data and browser events. We also design supervised and unsupervised learning architectures for real-time detection and offline attribution of human and automated agents, respectively. Information theoretic analysis and empirical evaluations are provided to show that multi-modal data analysis, as opposed to uni-modal analysis which relies solely on mouse movement dynamics, significantly improves time-to-detection and attribution accuracy. Various numerical evaluations using real-world data collected via WebGuard are provided achieving high accuracy in hundreds of milliseconds, with a communication overhead below 10 KB per second.
title In-Application Defense Against Evasive Web Scans through Behavioral Analysis
topic Machine Learning
Cryptography and Security
Information Theory
url https://arxiv.org/abs/2412.07005