Matches in SemOpenAlex for { <https://semopenalex.org/work/W2963878310> ?p ?o ?g. }
- W2963878310 abstract "The Extensible Markup Language (XML) is a complex language, and consequently, XML-based protocols are susceptible to entire classes of implicit and explicit security problems. Message formats in XML-based protocols are usually specified in XML Schema, and as a first-line defense, schema validation should reject malformed input. However, extension points in most protocol specifications break validation. Extension points are wildcards and considered best practice for loose composition, but they also enable an attacker to add unchecked content in a document, e.g., for a signature wrapping attack. This paper introduces datatyped XML visibly pushdown automata (dXVPAs) as language representation for mixed-content XML and presents an incremental learner that infers a dXVPA from example documents. The learner generalizes XML types and datatypes in terms of automaton states and transitions, and an inferred dXVPA converges to a good-enough approximation of the true language. The automaton is free from extension points and capable of stream validation, e.g., as an anomaly detector for XML-based protocols. For dealing with adversarial training data, two scenarios of poisoning are considered: a poisoning attack is either uncovered at a later time or remains hidden. Unlearning can therefore remove an identified poisoning attack from a dXVPA, and sanitization trims low-frequent states and transitions to get rid of hidden attacks. All algorithms have been evaluated in four scenarios, including a web service implemented in Apache Axis2 and Apache Rampart, where attacks have been simulated. In all scenarios, the learned automaton had zero false positives and outperformed traditional schema validation." @default.
- W2963878310 created "2019-07-30" @default.
- W2963878310 creator A5010248122 @default.
- W2963878310 date "2016-05-01" @default.
- W2963878310 modified "2023-09-23" @default.
- W2963878310 title "An Incremental Learner for Language-Based Anomaly Detection in XML" @default.
- W2963878310 cites W1265191870 @default.
- W2963878310 cites W138607541 @default.
- W2963878310 cites W1537258151 @default.
- W2963878310 cites W1608275671 @default.
- W2963878310 cites W174528657 @default.
- W2963878310 cites W1940611973 @default.
- W2963878310 cites W1969005071 @default.
- W2963878310 cites W1976526581 @default.
- W2963878310 cites W2013578787 @default.
- W2963878310 cites W2018888020 @default.
- W2963878310 cites W2019001600 @default.
- W2963878310 cites W2031469331 @default.
- W2963878310 cites W2037358873 @default.
- W2963878310 cites W2053118016 @default.
- W2963878310 cites W2057185776 @default.
- W2963878310 cites W2059078591 @default.
- W2963878310 cites W2071654679 @default.
- W2963878310 cites W2086070161 @default.
- W2963878310 cites W2099205674 @default.
- W2963878310 cites W2102851236 @default.
- W2963878310 cites W2103154003 @default.
- W2963878310 cites W2105472238 @default.
- W2963878310 cites W2105748890 @default.
- W2963878310 cites W2106527193 @default.
- W2963878310 cites W2109486375 @default.
- W2963878310 cites W2115087653 @default.
- W2963878310 cites W2115231916 @default.
- W2963878310 cites W2123229843 @default.
- W2963878310 cites W2124935488 @default.
- W2963878310 cites W2144638632 @default.
- W2963878310 cites W2151033407 @default.
- W2963878310 cites W2154467140 @default.
- W2963878310 cites W2154475850 @default.
- W2963878310 cites W2162840341 @default.
- W2963878310 cites W2569219525 @default.
- W2963878310 cites W2912451150 @default.
- W2963878310 cites W3099400694 @default.
- W2963878310 doi "https://doi.org/10.1109/spw.2016.35" @default.
- W2963878310 hasPublicationYear "2016" @default.
- W2963878310 type Work @default.
- W2963878310 sameAs 2963878310 @default.
- W2963878310 citedByCount "0" @default.
- W2963878310 crossrefType "proceedings-article" @default.
- W2963878310 hasAuthorship W2963878310A5010248122 @default.
- W2963878310 hasBestOaLocation W29638783102 @default.
- W2963878310 hasConcept C112505250 @default.
- W2963878310 hasConcept C11508877 @default.
- W2963878310 hasConcept C136764020 @default.
- W2963878310 hasConcept C199360897 @default.
- W2963878310 hasConcept C34330436 @default.
- W2963878310 hasConcept C34716815 @default.
- W2963878310 hasConcept C40713593 @default.
- W2963878310 hasConcept C41008148 @default.
- W2963878310 hasConcept C44883583 @default.
- W2963878310 hasConcept C55348073 @default.
- W2963878310 hasConcept C68699486 @default.
- W2963878310 hasConcept C80444323 @default.
- W2963878310 hasConcept C8797682 @default.
- W2963878310 hasConceptScore W2963878310C112505250 @default.
- W2963878310 hasConceptScore W2963878310C11508877 @default.
- W2963878310 hasConceptScore W2963878310C136764020 @default.
- W2963878310 hasConceptScore W2963878310C199360897 @default.
- W2963878310 hasConceptScore W2963878310C34330436 @default.
- W2963878310 hasConceptScore W2963878310C34716815 @default.
- W2963878310 hasConceptScore W2963878310C40713593 @default.
- W2963878310 hasConceptScore W2963878310C41008148 @default.
- W2963878310 hasConceptScore W2963878310C44883583 @default.
- W2963878310 hasConceptScore W2963878310C55348073 @default.
- W2963878310 hasConceptScore W2963878310C68699486 @default.
- W2963878310 hasConceptScore W2963878310C80444323 @default.
- W2963878310 hasConceptScore W2963878310C8797682 @default.
- W2963878310 hasLocation W29638783101 @default.
- W2963878310 hasLocation W29638783102 @default.
- W2963878310 hasOpenAccess W2963878310 @default.
- W2963878310 hasPrimaryLocation W29638783101 @default.
- W2963878310 hasRelatedWork W112893379 @default.
- W2963878310 hasRelatedWork W1506113601 @default.
- W2963878310 hasRelatedWork W1559018122 @default.
- W2963878310 hasRelatedWork W1699388987 @default.
- W2963878310 hasRelatedWork W1979919062 @default.
- W2963878310 hasRelatedWork W1990424408 @default.
- W2963878310 hasRelatedWork W2079707246 @default.
- W2963878310 hasRelatedWork W2105196373 @default.
- W2963878310 hasRelatedWork W2111548507 @default.
- W2963878310 hasRelatedWork W2119908482 @default.
- W2963878310 hasRelatedWork W2121659340 @default.
- W2963878310 hasRelatedWork W2122750998 @default.
- W2963878310 hasRelatedWork W2130702559 @default.
- W2963878310 hasRelatedWork W2141659075 @default.
- W2963878310 hasRelatedWork W2149765640 @default.
- W2963878310 hasRelatedWork W2294906419 @default.
- W2963878310 hasRelatedWork W2302673769 @default.
- W2963878310 hasRelatedWork W2375727884 @default.
- W2963878310 hasRelatedWork W2396720035 @default.