Web application firewall / Mohd Ikram Rahimi
The Web Application can easily be attacked by the hackers eventhough with the existence of the normal firewall in the system. This is due to the limitation that the normal firewall does not work in the application layer. The hackers will attack the Web Application using the methods like Struct...
Main Author: | |
---|---|
Format: | Student Project |
Published: |
Faculty of Information Technology and Quantitative Sciences
2006
|
Subjects: | |
Online Access: | http://ir.uitm.edu.my/id/eprint/677/ |
id |
uitm-677 |
---|---|
recordtype |
eprints |
spelling |
uitm-6772018-01-20T04:23:10Z http://ir.uitm.edu.my/id/eprint/677/ Web application firewall / Mohd Ikram Rahimi Rahimi, Mohd Ikram Electronic computers. Computer science Web databases The Web Application can easily be attacked by the hackers eventhough with the existence of the normal firewall in the system. This is due to the limitation that the normal firewall does not work in the application layer. The hackers will attack the Web Application using the methods like Structured Query Language (SQL) Injection, Cross Site Scripting (XSS), Command Injection, or Session Manipulation as the normal firewall only open port 80 for Internet connection. Most of the Web Application Firewall is quite costly. There are only few that can be operated under free license. The usage of ModSecurity can solve the problem as it can be downloaded under GNU license. This thesis is attempted to show the benefits of implementing ModSecurity and also the reverse proxy server, instead of just implementing the conventional web server. The penetration test is done to evaluate the performance of the server using this Web Application Firewall. The results showed that ModSecurity and the Reverse Proxy methods can improve the level of security for the web server by forbidding any intrusion to take place through the Web Application. The impacts of the attacks had caused severe damage to the server. The attacks also had congested the physical memory, CPU usage, and CPU clock with or without ModSecurity. Faculty of Information Technology and Quantitative Sciences 2006 Student Project NonPeerReviewed Rahimi, Mohd Ikram (2006) Web application firewall / Mohd Ikram Rahimi. [Student Project] (Unpublished) |
repository_type |
Digital Repository |
institution_category |
Local University |
institution |
Universiti Teknologi MARA |
building |
UiTM Institutional Repository |
collection |
Online Access |
topic |
Electronic computers. Computer science Web databases |
spellingShingle |
Electronic computers. Computer science Web databases Rahimi, Mohd Ikram Web application firewall / Mohd Ikram Rahimi |
description |
The Web Application can easily be attacked by the hackers eventhough with the
existence of the normal firewall in the system. This is due to the limitation that the
normal firewall does not work in the application layer. The hackers will attack the Web
Application using the methods like Structured Query Language (SQL) Injection, Cross
Site Scripting (XSS), Command Injection, or Session Manipulation as the normal firewall
only open port 80 for Internet connection. Most of the Web Application Firewall is quite
costly. There are only few that can be operated under free license. The usage of
ModSecurity can solve the problem as it can be downloaded under GNU license. This
thesis is attempted to show the benefits of implementing ModSecurity and also the
reverse proxy server, instead of just implementing the conventional web server. The
penetration test is done to evaluate the performance of the server using this Web
Application Firewall. The results showed that ModSecurity and the Reverse Proxy
methods can improve the level of security for the web server by forbidding any intrusion
to take place through the Web Application. The impacts of the attacks had caused severe
damage to the server. The attacks also had congested the physical memory, CPU usage,
and CPU clock with or without ModSecurity. |
format |
Student Project |
author |
Rahimi, Mohd Ikram |
author_facet |
Rahimi, Mohd Ikram |
author_sort |
Rahimi, Mohd Ikram |
title |
Web application firewall / Mohd Ikram Rahimi |
title_short |
Web application firewall / Mohd Ikram Rahimi |
title_full |
Web application firewall / Mohd Ikram Rahimi |
title_fullStr |
Web application firewall / Mohd Ikram Rahimi |
title_full_unstemmed |
Web application firewall / Mohd Ikram Rahimi |
title_sort |
web application firewall / mohd ikram rahimi |
publisher |
Faculty of Information Technology and Quantitative Sciences |
publishDate |
2006 |
url |
http://ir.uitm.edu.my/id/eprint/677/ |
first_indexed |
2023-09-18T22:44:52Z |
last_indexed |
2023-09-18T22:44:52Z |
_version_ |
1777417157090476032 |