发明授权
US08997232B2 Iterative automatic generation of attribute values for rules of a web application layer attack detector 有权
迭代自动生成Web应用层攻击检测器规则的属性值

Iterative automatic generation of attribute values for rules of a web application layer attack detector
摘要:
According to one embodiment, a computing device is coupled to a set of web application layer attack detectors (AD), which are coupled between HTTP clients and web application servers. The computing device learns a new set of attribute values for a set of attribute identifiers for each of a sequence of rules through an iterative process having a plurality of iterations. The iterative process begins with an attack specific rule, and the sequence of rules includes an attacker specific rule and another attack specific rule. Each iteration includes receiving a current alert package from one of the ADs sent responsive to a set of packets carrying a web application layer request meeting a condition of a current rule used by the AD, automatically generating a new set of attribute values based upon the current alert package, and transmitting the new set of attribute values to the set of ADs.
信息查询
0/0