International Journal of Advanced Research in IT and Engineering
  • Year: 2017
  • Volume: 6
  • Issue: 7

Open source rules for Real-Time protection of web server

  • Author:
  • Ekaterina Dudin1, Anna Otsetova2
  • Total Page Count: 9
  • Page Number: 13 to 21

1Asstt. Prof., PhD, University of Telecommunications and Post, Sofia, Bulgaria

2Asstt. Prof., PhD, University of Telecommunications and Post, Sofia, Bulgaria

Online published on 5 December, 2018.

Abstract

Modern web-based applications often remain open for hacker attacks and vulnerabilities of the server operating system. This fact requires the additional protection of the web server and the software it uses. This paper presents the main types of hacker attacks and the ability to prevent them using ModSecurity-based protection rules provided by Open Web Application Security Project. The ModSecurity modul, applying a set of rules for protection by inspecting incoming traffic and the response to these requests by the server was discussed. Practical results of their impact on various attacks-HTTP (fingerprinting), DoS (Denial of Service), DDoS (Distributed Denial of Service), SQL injections, etc. were presented.

Keywords

ModSecurity, Rules, HTTP fingerprinting, DoS, DDoS, SQL injections