1Asstt. Prof., PhD, University of Telecommunications and Post, Sofia, Bulgaria
2Asstt. Prof., PhD, University of Telecommunications and Post, Sofia, Bulgaria
Online published on 5 December, 2018.
Modern web-based applications often remain open for hacker attacks and vulnerabilities of the server operating system. This fact requires the additional protection of the web server and the software it uses. This paper presents the main types of hacker attacks and the ability to prevent them using ModSecurity-based protection rules provided by Open Web Application Security Project. The ModSecurity modul, applying a set of rules for protection by inspecting incoming traffic and the response to these requests by the server was discussed. Practical results of their impact on various attacks-HTTP (fingerprinting), DoS (Denial of Service), DDoS (Distributed Denial of Service), SQL injections, etc. were presented.
ModSecurity, Rules, HTTP fingerprinting, DoS, DDoS, SQL injections