Comparison of Anomaly Based and Signature Based Methods in Detection of Scanning Vulnerability

Ismail Puji Saputra, Ema Utami, Alva Hendi Muhammad · 2022

Information technology is mostly web-based which is required to be accessible anytime and anywhere, causing an increase in the chances of attacks on information technology. Attacks on websites usually begin with searching for loopholes on the website (website vulnerability scanning) using specific software that can find weaknesses on certain websites. Still, it will be hazardous if the person who knows the defects of the website is not someone who has authority over it. This study will discuss internet network security in detecting and anticipating scanning vulnerabilities using anomaly-based and signature-based methods. This research focused on using anomaly-based, and signature-based in detecting vulnerable scanner attacks, which is very different from other researchers were not considered vulnerable scanning as an attack. Anomaly-based is a technique for detecting an attack on a system. This technique involves attacking traffic patterns different from regular traffic in detecting irregularities. If there is irregular traffic, the traffic is considered an attack attempt. At the same time, signature-based is a matching technique packet from the user to the server. If the packet matches the database pattern, the packet will be considered an attack. The result of this research is to build an automated security mechanism for web vulnerability scanning attacks and compare the two methods in terms of speed and performance of detection methods.

Read the paper · More papers on PaperTik