Javascript must be enabled to continue!
WebGuard: Enhancing Web Security Through an Integrated Developer Platform
View through CrossRef
This research presents the development of an integrated developer platform named ‘WebGuard’. The proposedintegrated platform provides solutions for SQL Injection, Cookie and Session Hijacking, Cross-Site Scripting (XSS),Phishing, Distributed Denial-of-Service (DDoS) attacks, and Malware. This study used input validation by generatingautomated regular expressions to detect SQL injection. In addition, stored procedures, parameterized queries, andcryptography are used to detect SQL injection. This platform used secure session ID generation and encrypted userauthentication to prevent cookie and session hijacking. Here, libsodium is utilized to decrypt user authentication. In thisstudy, the cross-site scripting (XSS) mitigation employs input validation, output encoding, and DOMPurify for advancedsanitization. Distributed Denial-of-Service (DDoS) uses a Content Delivery Network (CDN) inWebguard that contains loadbalancing, rate limiting, and a comprehensive incident response plan. Webguard provided malware detection service byusing file type and size validation and heuristic checks. Furthermore, Phishing attacks are also prevented by the proposedplatform. The proposed platform successfully prevented 92.77% of SQL injection attacks out of 828 samples, and it detected6.16% of the provided samples. Webguard successfully prevented 95.12% of cookie and session hijacking attacks out of 41samples. The platform successfully prevented 90.95%, and detected 7.41% of XSS attacks, out of 243 samples. This platformsuccessfully prevented 81.82% of DDoS attacks out of 11 samples. In phishing detection, Webguard successfully detected92.64% out of 231 samples. Finally, this platform successfully detected 87.88% of malware out of 33 samples. Therefore,WebGuard promotes a safer online environment and makes secure development easier for programmers by combining thesefeatures in one location.
International Academic Press
Title: WebGuard: Enhancing Web Security Through an Integrated Developer Platform
Description:
This research presents the development of an integrated developer platform named ‘WebGuard’.
The proposedintegrated platform provides solutions for SQL Injection, Cookie and Session Hijacking, Cross-Site Scripting (XSS),Phishing, Distributed Denial-of-Service (DDoS) attacks, and Malware.
This study used input validation by generatingautomated regular expressions to detect SQL injection.
In addition, stored procedures, parameterized queries, andcryptography are used to detect SQL injection.
This platform used secure session ID generation and encrypted userauthentication to prevent cookie and session hijacking.
Here, libsodium is utilized to decrypt user authentication.
In thisstudy, the cross-site scripting (XSS) mitigation employs input validation, output encoding, and DOMPurify for advancedsanitization.
Distributed Denial-of-Service (DDoS) uses a Content Delivery Network (CDN) inWebguard that contains loadbalancing, rate limiting, and a comprehensive incident response plan.
Webguard provided malware detection service byusing file type and size validation and heuristic checks.
Furthermore, Phishing attacks are also prevented by the proposedplatform.
The proposed platform successfully prevented 92.
77% of SQL injection attacks out of 828 samples, and it detected6.
16% of the provided samples.
Webguard successfully prevented 95.
12% of cookie and session hijacking attacks out of 41samples.
The platform successfully prevented 90.
95%, and detected 7.
41% of XSS attacks, out of 243 samples.
This platformsuccessfully prevented 81.
82% of DDoS attacks out of 11 samples.
In phishing detection, Webguard successfully detected92.
64% out of 231 samples.
Finally, this platform successfully detected 87.
88% of malware out of 33 samples.
Therefore,WebGuard promotes a safer online environment and makes secure development easier for programmers by combining thesefeatures in one location.
Related Results
A Study on Transforming the GTI(Greater Tumen Initiative) into Infrastructure Developer in Northeast Asia
A Study on Transforming the GTI(Greater Tumen Initiative) into Infrastructure Developer in Northeast Asia
The purpose of this study was to find the need to develop GTI into a Northeast Asia developer, and to reorganize and develop the current GTI. Through the study, we found that there...
A Study on Transforming the GTI(Greater Tumen Initiative) into Infrastructure Developer in Northeast Asia
A Study on Transforming the GTI(Greater Tumen Initiative) into Infrastructure Developer in Northeast Asia
The purpose of this study was to find the need to develop GTI into a Northeast Asia developer, and to reorganize and develop the current GTI. Through the study, we found that there...
Development Tasks of AI-based Security Industry
Development Tasks of AI-based Security Industry
Recently, the government's interest in industries utilizing AI has been amplified, with initiatives such as announcing a roadmap aiming to achieve the goal of becoming the world's ...
TANGGUNG JAWAB HUKUM DEVELOPER DALAM TRANSAKSAKSI JUAL BELI SISTEM PPJB
TANGGUNG JAWAB HUKUM DEVELOPER DALAM TRANSAKSAKSI JUAL BELI SISTEM PPJB
AbstrakPerkembangan dalam dunia usaha property sangat menarik minat palaku usaha sehingga dengan konsep market yang menjajikan maka developer selaku pengembang secara aspek hukum m...
Web Mining for Public E-Services Personalization
Web Mining for Public E-Services Personalization
Over the last decade, we have witnessed an explosive growth in the information available on the Web. Today, Web browsers provide easy access to myriad sources of text and multimedi...
Web Mining for Public E-Services Personalization
Web Mining for Public E-Services Personalization
Over the last decade, we have witnessed an explosive growth in the information available on the Web. Today, Web browsers provide easy access to myriad sources of text and multimedi...
ESSENTIAL SECURITY PRACTICES FOR FORTIFYING MOBILE APPS
ESSENTIAL SECURITY PRACTICES FOR FORTIFYING MOBILE APPS
“Essential Security Practices for Fortifying Mobile Apps” is a definitive guide designed to empower developers, security professionals, and organizations with the knowledge and too...
GERMANY'S SECURITY MANAGEMENT IN THE LIGHT OF THE INTEGRATED SECURITY – CURRENT STATE AND PROSPECTS
GERMANY'S SECURITY MANAGEMENT IN THE LIGHT OF THE INTEGRATED SECURITY – CURRENT STATE AND PROSPECTS
In June 2023, the Federal Government of Germany presented the first national security strategy (NSS). The NSS promotes Integrated Security as a new foreign and security policy. How...

