Vulnerable Web Server Protection by Hash Based URL Transformation

Ryuya Uda · 2020

Development of Internet has changed reservation, submission and registration from paper or phone to online. Some big companies provide integrated services to hotels, restaurants, shops, etc. and the services are more secure than those by small companies since web engineers in such big companies are educated enough in information security. On the other hand, many small hotels, restaurants, shops, etc. also have their own web sites and sometimes web services on the sites are vulnerable by wrong settings or ignoring to switch off a test mode. Moreover, many IoT devices become popular and are sometimes set in wrong way. Therefore, in this paper, I propose a protection method of vulnerable web servers by hash based URL transformation. A filter of the method is set in a pseudo web server and the server works as an original web server while passing through HTTP communication between client computers and the actual web server. Administrators of actual web servers are not required special settings and any vulnerable URL is divided from the official web services. The proposed method was evaluated and its performance is written in this paper.

Read the paper · More papers on PaperTik