Collected research
BLOCK: A Black-Box Approach for Detection of State Violation Attacks Towards Web Applications
BLOCK: a black-box approach for detection of state violation attacks towards web applications
BLOCK infers a web application's intended behaviour model from attack-free traffic alone, extracting invariants over request/response sequences and their associated session variable values. At runtime any request or response violating its invariants is flagged as a state violation attack. Built on the WebScarab proxy, it needs no source code and was evaluated on real applications.
Record
- Document
- BLOCK: a black-box approach for detection of state violation attacks towards web applications
- Researcher
- Xiaowei Li and Yuan Xue
- Published by
- ptolemy.berkeley.edu
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Xiaowei Li and Yuan Xue, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .