International Conference on Advances in Science and Technology |
Foundation of Computer Science USA |
ICAST2014 - Number 1 |
February 2015 |
Authors: Sireesha C, Jyostna G, Raghuvaran P, P R L Eswari |
deaa0306-e1db-4b49-918f-0aa6f1b4165a |
Sireesha C, Jyostna G, Raghuvaran P, P R L Eswari . AnDeWA: An Approach for Analyzing and Detecting Work Flow Deviation Attacks in Web Applications. International Conference on Advances in Science and Technology. ICAST2014, 1 (February 2015), 6-11.
Workflow deviations in web application occur due to logical flaws left while designing, implementing and hosting the web application. It is really hard to find the workflow deviations in web applications without accessing the website database and the application sensitive information. In this paper, AnDeWA is presented as a lightweight approach for detecting the workflow deviations in web applications with the minimum prerequisites of users to role binding information. AnDeWA follows the dynamic analysis technique which analyzes the web application behavior at a run time to detect the workflow deviation attacks.