: Attack-aware applications compared against a web application firewall and an intrusion detection system
Thomassen, Pål 2012 (English)
The thesis takes a look at the OWASP AppSensor project. The OWASP AppSensor project is about the idea of detecting attacks inside the applicaiton. The thesis compares OWASP AppSensor against both a web application firewall and an intrusion detection system. The comparison is based both on a short litterature study and an experiment performed. The experiment was a set of attacks based on OWASP top ten list which were executed against a simple bank web application. In the experiment the intrusion detection systems, web application firewall and the AppSensor detection points inside the application was tested to see which attacks they where able to detect. The results were quite satisfying for both the web application firewall and AppSensor meanin that they detected many attacks but AppSensors detection was slightly better.
Place, publisher, year, pages
Institutt for datateknikk og informasjonsvitenskap, 2012. 130 p.
ntnudaim:7161, MTDT datateknikk, Program- og informasjonssystemer
Identifiersurn:nbn:no:ntnu:diva-18576 (URN)ntnudaim:7161 (Local ID)oai:DiVA.org:ntnu-18576 (OAI)diva2:566091 (DiVA)
Røstad, LillianOftedal, Erlend