Zero-Day Exploits in Web Applications: Detection, Response, and Prevention
Subrat Jena, Ashutosh Soni, Jayanti Rout, Surendra Kumar Nanda · 2024
Cybercriminals are increasingly exploiting zero-day vulnerabilities in web applications to compromise the security and integrity of online systems. These vulnerabilities were previously unknown even to the developers, and the term “zero-day” refers to the time window available to web application developers to patch the vulnerability before it can be exploited. The current defense mechanisms against zero-day attacks in web applications focus on detection and response, which often fail against new or unknown vulnerabilities. In order to resolve this issue, we suggest a novel zero-day attack identification and mitigation technique for web applications. Our approach utilizes a modified sandbox tool, named VMware Workstation Pro, to isolate infected web applications and prevent the spread of malware. Our experiments, conducted on a Linux-based web server, demonstrate that our proposed design successfully stops zero-day malware and prevents it from infesting other web applications.