{"id":1516,"date":"2023-04-11T12:54:55","date_gmt":"2023-04-11T10:54:55","guid":{"rendered":"https:\/\/dtstc.ugr.es\/neus-cslab\/?page_id=1516"},"modified":"2023-04-21T09:03:38","modified_gmt":"2023-04-21T07:03:38","slug":"web","status":"publish","type":"page","link":"https:\/\/dtstc.ugr.es\/neus-cslab\/lineas-de-investigacion\/web\/","title":{"rendered":"Seguridad en web"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"1516\" class=\"elementor elementor-1516\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-e4e972e elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"e4e972e\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2d2bf1a\" data-id=\"2d2bf1a\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-af31eea elementor-widget elementor-widget-heading\" data-id=\"af31eea\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Seguridad en web<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8f6ac55 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"8f6ac55\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p style=\"text-align: justify; text-indent: 20pt; line-height: 150%; font-family: 'Lato',serif; font-style: normal; font-weight: 300; justify-content: align; font-size: 100%;\"><img fetchpriority=\"high\" decoding=\"async\" class=\"alignleft size-full wp-image-483\" src=\"\/neus-cslab\/wp-content\/uploads\/2022\/03\/linea-https.jpg\" alt=\"\" width=\"291\" height=\"193\" \/>\nLos servicios web han experimentado una gran expansi\u00f3n en los \u00faltimos a\u00f1os, tanto por el desarrollo de servicios cada\nvez m\u00e1s complejos y avanzados como por la f\u00e1cil accesibilidad a los mismos mediante el uso de navegadores. Consecuentemente, los servidores web se han convertido en una de las dianas favoritas de los ciberataques. Entre otros\nescenarios, los servidores comprometidos se utilizan habitualmente para la distribuci\u00f3n de malware, para realizar <i>phishing<\/i> o como puerta de acceso a la red de una empresa.<\/p>\n<p style=\"text-align: justify; text-indent: 20pt; line-height: 150%; font-family: 'Lato',serif; font-style: normal; font-weight: 300; justify-content: align; font-size: 100%;\">Esta es una de las <strong>l\u00edneas principales de investigaci\u00f3n <\/strong> del grupo, que se apoya, fundamentalmente, en la l\u00ednea de investigaci\u00f3n en detecci\u00f3n de intrusiones. Nuesto objetivo es el desarrollo de sistemas que permitan proteger los servidores web a partir de la identificaci\u00f3n de amenazas y ataques. Esta l\u00ednea se complementa con la de seguridad en IoT ya que muchos de los servicios subyacentes en IoT operan o pueden operar a trav\u00e9s de servicios basados en web.<\/p>\n<p style=\"text-align: justify; text-indent: 20pt; line-height: 150%; font-family: 'Lato',serif; font-style: normal; font-weight: 300; justify-content: align; font-size: 100%;\">Hemos realizado contribuciones especialmente en la <b>detecci\u00f3n de ataques<\/b> basados en <b>peticiones HTTP<\/b>, tanto a partir de la detecci\u00f3n basada en firmas como en anomal\u00edas. Tambi\u00e9n en sistemas h\u00edbridos que combinen varias tecnolog\u00edas de detecci\u00f3n y en cuestiones relacionadas con la evaluaci\u00f3n adecuada de las capacidades de protecci\u00f3n proporcionadas por los sistemas desarrollados. Para ello hemos adquirido y etiquetado varios datasets de <b>tr\u00e1fico HTTP real<\/b> para su uso con fines de investigaci\u00f3n.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f20a9b1 elementor-widget elementor-widget-image\" data-id=\"f20a9b1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t<figure class=\"wp-caption\">\n\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/dtstc.ugr.es\/neus-cslab\/wp-content\/uploads\/elementor\/thumbs\/generacion-firmas-foco-q5buqui331iiu0tnpre67p70sof2ag7ez2p8a0ir1g.png\" title=\"generacion-firmas-foco\" alt=\"generacion-firmas-foco\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t<figcaption class=\"widget-image-caption wp-caption-text\">Diagrama sistema generaci\u00f3n de firmas para HTTP<\/figcaption>\n\t\t\t\t\t\t\t\t\t\t<\/figure>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-1223443 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"1223443\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-e913e57\" data-id=\"e913e57\" data-element_type=\"column\" data-e-type=\"column\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-af28f5d elementor-widget elementor-widget-text-editor\" data-id=\"af28f5d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h3><span style=\"color: #0a3824;\">L\u00edneas de trabajo<\/span><\/h3><ul><li><p style=\"text-align: justify; line-height: normal;\"><strong>Adquisici\u00f3n y etiquetado<\/strong> de tr\u00e1fico HTTP en<strong> escenarios reales<\/strong><\/p><\/li><li><p style=\"text-align: justify; line-height: normal;\">An\u00e1lisis de <strong>vulnerabilidades<\/strong> en servicios web<\/p><\/li><li><p style=\"text-align: justify; line-height: normal;\">An\u00e1lisis de <strong>trazas<\/strong> de servidores web<\/p><\/li><li><p style=\"text-align: justify; line-height: normal;\"><strong>Metodolog\u00edas de evaluaci\u00f3n<\/strong> de sistemas de detecci\u00f3n para web<\/p><\/li><li><p style=\"text-align: justify; line-height: normal;\">Generaci\u00f3n<strong> autom\u00e1tica de firmas <\/strong>para el servicio HTTP<\/p><\/li><li><p style=\"text-align: justify; line-height: normal;\">Generaci\u00f3n de <strong>datasets de ataques<\/strong> HTTP<\/p><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-c249292\" data-id=\"c249292\" data-element_type=\"column\" data-e-type=\"column\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-9b7e90b elementor-widget elementor-widget-text-editor\" data-id=\"9b7e90b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h3><span style=\"color: #0a3824;\">T\u00e9cnicas \/ m\u00e9todos\n<\/span><\/h3>\n<ul>\n \t<li>\n<p style=\"text-align: justify; line-height: normal;\">Modelado de Markov<\/p>\n<\/li>\n \t<li>\n<p style=\"text-align: justify; line-height: normal;\">An\u00e1lisis de cadenas<\/p>\n<\/li>\n \t<li>\n<p style=\"text-align: justify; line-height: normal;\">Aprendizaje autom\u00e1tico<\/p>\n<\/li>\n \t<li>\n<p style=\"text-align: justify; line-height: normal;\">An\u00e1lisis de series temporales<\/p>\n<\/li>\n \t<li><p style=\"text-align: justify; line-height: normal;\">Comparaci\u00f3n de patrones<\/li>\n \t<li><p style=\"text-align: justify; line-height: normal;\">Correlaci\u00f3n de eventos<\/li>\n<\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-5eb5f14 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"5eb5f14\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-33 elementor-inner-column elementor-element elementor-element-d769f74\" data-id=\"d769f74\" data-element_type=\"column\" data-e-type=\"column\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t<div class=\"elementor-background-overlay\"><\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-33 elementor-inner-column elementor-element elementor-element-613982e\" data-id=\"613982e\" data-element_type=\"column\" data-e-type=\"column\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-90b0b64 elementor-widget elementor-widget-text-editor\" data-id=\"90b0b64\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h3><span style=\"color: #0a3824;\">Resultados relevantes<br \/><\/span><\/h3><ul><li><p style=\"text-align: justify; line-height: normal;\">Prototipo de sistema de generaci\u00f3n autom\u00e1tica de firmas para HTTP<\/p><\/li><li>Varios datasets de peticiones HTTP reales etiquetadas (ground-truth)<\/li><li>Inspectorlog: detecci\u00f3n de ataques basada en firmas sobre trazas HTTP<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-33 elementor-inner-column elementor-element elementor-element-c7a4a36\" data-id=\"c7a4a36\" data-element_type=\"column\" data-e-type=\"column\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-a78e8af elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"a78e8af\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-a051be7\" data-id=\"a051be7\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-81abaea elementor-widget elementor-widget-heading\" data-id=\"81abaea\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Publicaciones destacadas<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a7c28d6 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"a7c28d6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><div class=\"teachpress_pub_list\"><form name=\"tppublistform\" method=\"get\"><a name=\"tppubs\" id=\"tppubs\"><\/a><\/form><div class=\"teachpress_publication_list\"><div class=\"tp_publication tp_publication_article\"><div class=\"tp_pub_info\"><p class=\"tp_pub_author\"> D\u00edaz-Verdejo, Jes\u00fas E.;  Estepa Alonso, Rafael;  Estepa Alonso, Antonio;  Mu\u00f1oz-Calle, F. J.;  Madinabeitia, German<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('496','tp_links')\" style=\"cursor:pointer;\">Building a large, realistic and labeled HTTP URI dataset for anomaly-based intrusion detection systems: Biblio-US17 <\/a> <span class=\"tp_pub_type tp_  article\">Art\u00edculo de revista<\/span> <\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">En: <\/span><span class=\"tp_pub_additional_journal\">Cybersecurity, <\/span><span class=\"tp_pub_additional_volume\">vol. 8, <\/span><span class=\"tp_pub_additional_number\">no 35, <\/span><span class=\"tp_pub_additional_year\">2025<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2523-3246<\/span>.<\/p><p class=\"tp_pub_menu\"><span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_496\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('496','tp_abstract')\" title=\"Mostrar resumen\" style=\"cursor:pointer;\">Resumen<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_496\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('496','tp_links')\" title=\"Mostrar enlaces y recursos\" style=\"cursor:pointer;\">Enlaces<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_496\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('496','tp_bibtex')\" title=\"Mostrar entrada BibTeX \" style=\"cursor:pointer;\">BibTeX<\/a><\/span><\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_496\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{Biblio24,<br \/>\r\ntitle = {Building a large, realistic and labeled HTTP URI dataset for anomaly-based intrusion detection systems: Biblio-US17 },<br \/>\r\nauthor = {Jes\u00fas E. {D\u00edaz-Verdejo} and {Estepa Alonso}, Rafael and {Estepa Alonso}, Antonio and F. J. {Mu\u00f1oz-Calle} and German {Madinabeitia}},<br \/>\r\ndoi = {https:\/\/doi.org\/10.1186\/s42400\u2011024\u201100336\u20113},<br \/>\r\nissn = {2523-3246},<br \/>\r\nyear  = {2025},<br \/>\r\ndate = {2025-06-05},<br \/>\r\nurldate = {2025-06-05},<br \/>\r\njournal = {Cybersecurity},<br \/>\r\nvolume = {8},<br \/>\r\nnumber = {35},<br \/>\r\nabstract = {This paper introduces Biblio-US17, a labeled dataset collected over 6 months from the log files of a popular public website at the University of Seville. It contains 47 million records, each including the method, uniform resource identifier (URI) and associated response code and size of every request received by the web server. Records have been classified as either normal or attack using a comprehensive semi-automated process, which involved signature-based detection, assisted inspection of URIs vocabulary, and substantial expert manual supervision. Unlike comparable datasets, this one offers a genuine real-world perspective on the normal operation of an active website, along with an unbiased proportion of actual attacks (i.e., non-synthetic). This makes it ideal for evaluating and comparing anomalybased approaches in a realistic environment. Its extensive size and duration also make it valuable for addressing challenges like data shift and insufficient training. This paper describes the collection and labeling processes, dataset structure, and most relevant properties. We also include an example of an application for assessing the performance of a simple anomaly detector. Biblio-US17, now available to the scientific community, can also be used to model the URIs used by current web servers.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('496','tp_bibtex')\">Cerrar<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_496\" style=\"display:none;\"><div class=\"tp_abstract_entry\">This paper introduces Biblio-US17, a labeled dataset collected over 6 months from the log files of a popular public website at the University of Seville. It contains 47 million records, each including the method, uniform resource identifier (URI) and associated response code and size of every request received by the web server. Records have been classified as either normal or attack using a comprehensive semi-automated process, which involved signature-based detection, assisted inspection of URIs vocabulary, and substantial expert manual supervision. Unlike comparable datasets, this one offers a genuine real-world perspective on the normal operation of an active website, along with an unbiased proportion of actual attacks (i.e., non-synthetic). This makes it ideal for evaluating and comparing anomalybased approaches in a realistic environment. Its extensive size and duration also make it valuable for addressing challenges like data shift and insufficient training. This paper describes the collection and labeling processes, dataset structure, and most relevant properties. We also include an example of an application for assessing the performance of a simple anomaly detector. Biblio-US17, now available to the scientific community, can also be used to model the URIs used by current web servers.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('496','tp_abstract')\">Cerrar<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_496\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/https:\/\/doi.org\/10.1186\/s42400\u2011024\u201100336\u20113\" title=\"DOI de seguimiento:https:\/\/doi.org\/10.1186\/s42400\u2011024\u201100336\u20113\" target=\"_blank\">doi:https:\/\/doi.org\/10.1186\/s42400\u2011024\u201100336\u20113<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('496','tp_links')\">Cerrar<\/a><\/p><\/div><\/div><\/div><div class=\"tp_publication tp_publication_article\"><div class=\"tp_pub_info\"><p class=\"tp_pub_author\"> D\u00edaz-Verdejo, Jes\u00fas E.;  Estepa Alonso, Rafael;  Estepa Alonso, Antonio;  Madinabeitia, German<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('264','tp_links')\" style=\"cursor:pointer;\">A critical review of the techniques used for anomaly detection of HTTP-based attacks: taxonomy, limitations and open challenges<\/a> <span class=\"tp_pub_type tp_  article\">Art\u00edculo de revista<\/span> <\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">En: <\/span><span class=\"tp_pub_additional_journal\">Computers and Security, <\/span><span class=\"tp_pub_additional_volume\">vol. 124, <\/span><span class=\"tp_pub_additional_pages\">pp. 102997, <\/span><span class=\"tp_pub_additional_year\">2023<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 01674048<\/span>.<\/p><p class=\"tp_pub_menu\"><span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_264\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('264','tp_abstract')\" title=\"Mostrar resumen\" style=\"cursor:pointer;\">Resumen<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_264\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('264','tp_links')\" title=\"Mostrar enlaces y recursos\" style=\"cursor:pointer;\">Enlaces<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_264\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('264','tp_bibtex')\" title=\"Mostrar entrada BibTeX \" style=\"cursor:pointer;\">BibTeX<\/a><\/span><\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_264\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{Diaz-Verdejo2023,<br \/>\r\ntitle = {A critical review of the techniques used for anomaly detection of HTTP-based attacks: taxonomy, limitations and open challenges},<br \/>\r\nauthor = {Jes\u00fas E. D\u00edaz-Verdejo and {Estepa Alonso}, Rafael and {Estepa Alonso}, Antonio and German Madinabeitia},<br \/>\r\ndoi = {10.1016\/j.cose.2022.102997},<br \/>\r\nissn = {01674048},<br \/>\r\nyear  = {2023},<br \/>\r\ndate = {2023-01-01},<br \/>\r\nurldate = {2023-01-01},<br \/>\r\njournal = {Computers and Security},<br \/>\r\nvolume = {124},<br \/>\r\npages = {102997},<br \/>\r\nabstract = {Intrusion Detection Systems (IDSs) and Web Application Firewalls (WAFs) offer a crucial layer of defense that allows organizations to detect cyberattacks on their web servers. Academic research overwhelmingly suggests using anomaly detection techniques to improve the performance of these defensive systems. However, analyzing and comparing the wide range of solutions in the scientific literature is challenging since they are typically presented as isolated (unrelated) contributions, and their results cannot be generalized. We believe that this impairs the industry&#039;s adoption of academic results and the advancement of research in this field. This paper aims to shed light on the literature on anomaly-based detection of attacks that use HTTP request messages. We define a novel framework for anomaly detection based on six data processing steps grouped into two sequential phases: preprocessing and classification. Based on this framework, we provide a taxonomy and critical review of the techniques surveyed, emphasizing their limitations and applicability. Future approaches should take advantage of the syntax and semantics of the Uniform Resource Locator (URL), be scalable, and address their obsolescence. These aspects are frequently overlooked in the literature and pose a significant challenge in the current era of web services. For better comparability, authors should use adequate public datasets, follow a thorough methodology, and use appropriate metrics that fully show the pros and cons of the approach.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('264','tp_bibtex')\">Cerrar<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_264\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Intrusion Detection Systems (IDSs) and Web Application Firewalls (WAFs) offer a crucial layer of defense that allows organizations to detect cyberattacks on their web servers. Academic research overwhelmingly suggests using anomaly detection techniques to improve the performance of these defensive systems. However, analyzing and comparing the wide range of solutions in the scientific literature is challenging since they are typically presented as isolated (unrelated) contributions, and their results cannot be generalized. We believe that this impairs the industry&#039;s adoption of academic results and the advancement of research in this field. This paper aims to shed light on the literature on anomaly-based detection of attacks that use HTTP request messages. We define a novel framework for anomaly detection based on six data processing steps grouped into two sequential phases: preprocessing and classification. Based on this framework, we provide a taxonomy and critical review of the techniques surveyed, emphasizing their limitations and applicability. Future approaches should take advantage of the syntax and semantics of the Uniform Resource Locator (URL), be scalable, and address their obsolescence. These aspects are frequently overlooked in the literature and pose a significant challenge in the current era of web services. For better comparability, authors should use adequate public datasets, follow a thorough methodology, and use appropriate metrics that fully show the pros and cons of the approach.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('264','tp_abstract')\">Cerrar<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_264\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.cose.2022.102997\" title=\"DOI de seguimiento:10.1016\/j.cose.2022.102997\" target=\"_blank\">doi:10.1016\/j.cose.2022.102997<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('264','tp_links')\">Cerrar<\/a><\/p><\/div><\/div><\/div><div class=\"tp_publication tp_publication_article\"><div class=\"tp_pub_info\"><p class=\"tp_pub_author\"> D\u00edaz-Verdejo, J. E.;  Mu\u00f1oz-Calle, F. J.;  Estepa Alonso, A.;  Estepa Alonso, R.;  Madinabeitia, G.<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('263','tp_links')\" style=\"cursor:pointer;\">On the Detection Capabilities of Signature-Based Intrusion Detection Systems in the Context of Web Attacks<\/a> <span class=\"tp_pub_type tp_  article\">Art\u00edculo de revista<\/span> <\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">En: <\/span><span class=\"tp_pub_additional_journal\">Applied Sciences, <\/span><span class=\"tp_pub_additional_volume\">vol. 12, <\/span><span class=\"tp_pub_additional_number\">no 2, <\/span><span class=\"tp_pub_additional_pages\">pp. 852, <\/span><span class=\"tp_pub_additional_year\">2022<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 20763417<\/span>.<\/p><p class=\"tp_pub_menu\"><span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_263\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('263','tp_abstract')\" title=\"Mostrar resumen\" style=\"cursor:pointer;\">Resumen<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_263\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('263','tp_links')\" title=\"Mostrar enlaces y recursos\" style=\"cursor:pointer;\">Enlaces<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_263\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('263','tp_bibtex')\" title=\"Mostrar entrada BibTeX \" style=\"cursor:pointer;\">BibTeX<\/a><\/span><\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_263\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{Diaz-Verdejo2022,<br \/>\r\ntitle = {On the Detection Capabilities of Signature-Based Intrusion Detection Systems in the Context of Web Attacks},<br \/>\r\nauthor = {J. E. D\u00edaz-Verdejo and F. J. Mu\u00f1oz-Calle and {Estepa Alonso}, A. and {Estepa Alonso}, R. and G. Madinabeitia},<br \/>\r\nurl = {https:\/\/www.mdpi.com\/2076-3417\/12\/2\/852\/htm https:\/\/www.mdpi.com\/2076-3417\/12\/2\/852},<br \/>\r\ndoi = {10.3390\/app12020852},<br \/>\r\nissn = {20763417},<br \/>\r\nyear  = {2022},<br \/>\r\ndate = {2022-01-01},<br \/>\r\nurldate = {2022-01-01},<br \/>\r\njournal = {Applied Sciences},<br \/>\r\nvolume = {12},<br \/>\r\nnumber = {2},<br \/>\r\npages = {852},<br \/>\r\npublisher = {Multidisciplinary Digital Publishing Institute},<br \/>\r\nabstract = {Signature-based Intrusion Detection Systems (SIDS) play a crucial role within the arsenal of security components of most organizations. They can find traces of known attacks in the network traffic or host events for which patterns or signatures have been pre-established. SIDS include standard packages of detection rulesets, but only those rules suited to the operational environment should be activated for optimal performance. However, some organizations might skip this tuning process and instead activate default off-the-shelf rulesets without understanding its implications and trade-offs. In this work, we help gain insight into the consequences of using predefined rulesets in the performance of SIDS. We experimentally explore the performance of three SIDS in the context of web attacks. In particular, we gauge the detection rate obtained with predefined subsets of rules for Snort, ModSecurity and Nemesida using seven attack datasets. We also determine the precision and rate of alert generated by each detector in a real-life case using a large trace from a public webserver. Results show that the maximum detection rate achieved by the SIDS under test is insufficient to protect systems effectively and is lower than expected for known attacks. Our results also indicate that the choice of predefined settings activated on each detector strongly influences its detection capability and false alarm rate. Snort and ModSecurity scored either a very poor detection rate (activating the less-sensitive predefined ruleset) or a very poor precision (activating the full ruleset). We also found that using various SIDS for a cooperative decision can improve the precision or the detection rate, but not both. Consequently, it is necessary to reflect upon the role of these open-source SIDS with default configurations as core elements for protection in the context of web attacks. Finally, we provide an efficient method for systematically determining which rules deactivate from a ruleset to significantly reduce the false alarm rate for a target operational environment. We tested our approach using Snort&rsquo;s ruleset in our real-life trace, increasing the precision from 0.015 to 1 in less than 16 h of work.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('263','tp_bibtex')\">Cerrar<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_263\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Signature-based Intrusion Detection Systems (SIDS) play a crucial role within the arsenal of security components of most organizations. They can find traces of known attacks in the network traffic or host events for which patterns or signatures have been pre-established. SIDS include standard packages of detection rulesets, but only those rules suited to the operational environment should be activated for optimal performance. However, some organizations might skip this tuning process and instead activate default off-the-shelf rulesets without understanding its implications and trade-offs. In this work, we help gain insight into the consequences of using predefined rulesets in the performance of SIDS. We experimentally explore the performance of three SIDS in the context of web attacks. In particular, we gauge the detection rate obtained with predefined subsets of rules for Snort, ModSecurity and Nemesida using seven attack datasets. We also determine the precision and rate of alert generated by each detector in a real-life case using a large trace from a public webserver. Results show that the maximum detection rate achieved by the SIDS under test is insufficient to protect systems effectively and is lower than expected for known attacks. Our results also indicate that the choice of predefined settings activated on each detector strongly influences its detection capability and false alarm rate. Snort and ModSecurity scored either a very poor detection rate (activating the less-sensitive predefined ruleset) or a very poor precision (activating the full ruleset). We also found that using various SIDS for a cooperative decision can improve the precision or the detection rate, but not both. Consequently, it is necessary to reflect upon the role of these open-source SIDS with default configurations as core elements for protection in the context of web attacks. Finally, we provide an efficient method for systematically determining which rules deactivate from a ruleset to significantly reduce the false alarm rate for a target operational environment. We tested our approach using Snort&amp;rsquo;s ruleset in our real-life trace, increasing the precision from 0.015 to 1 in less than 16 h of work.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('263','tp_abstract')\">Cerrar<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_263\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.mdpi.com\/2076-3417\/12\/2\/852\/htm https:\/\/www.mdpi.com\/2076-3417\/12\/2\/852\" title=\"https:\/\/www.mdpi.com\/2076-3417\/12\/2\/852\/htm https:\/\/www.mdpi.com\/2076-3417\/12\/2\/[...]\" target=\"_blank\">https:\/\/www.mdpi.com\/2076-3417\/12\/2\/852\/htm https:\/\/www.mdpi.com\/2076-3417\/12\/2\/[&#8230;]<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.3390\/app12020852\" title=\"DOI de seguimiento:10.3390\/app12020852\" target=\"_blank\">doi:10.3390\/app12020852<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('263','tp_links')\">Cerrar<\/a><\/p><\/div><\/div><\/div><div class=\"tp_publication tp_publication_article\"><div class=\"tp_pub_info\"><p class=\"tp_pub_author\"> D\u00edaz-Verdejo, Jes\u00fas E.;  Estepa, Antonio;  Estepa, Rafael;  Madinabeitia, German;  Mu\u00f1oz-Calle, Fco Javier<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('274','tp_links')\" style=\"cursor:pointer;\">A methodology for conducting efficient sanitization of HTTP training datasets<\/a> <span class=\"tp_pub_type tp_  article\">Art\u00edculo de revista<\/span> <\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">En: <\/span><span class=\"tp_pub_additional_journal\">Future Generation Computer Systems, <\/span><span class=\"tp_pub_additional_volume\">vol. 109, <\/span><span class=\"tp_pub_additional_pages\">pp. 67\u201382, <\/span><span class=\"tp_pub_additional_year\">2020<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 0167739X<\/span>.<\/p><p class=\"tp_pub_menu\"><span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_274\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('274','tp_abstract')\" title=\"Mostrar resumen\" style=\"cursor:pointer;\">Resumen<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_274\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('274','tp_links')\" title=\"Mostrar enlaces y recursos\" style=\"cursor:pointer;\">Enlaces<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_274\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('274','tp_bibtex')\" title=\"Mostrar entrada BibTeX \" style=\"cursor:pointer;\">BibTeX<\/a><\/span><\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_274\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{Diaz-Verdejo2020,<br \/>\r\ntitle = {A methodology for conducting efficient sanitization of HTTP training datasets},<br \/>\r\nauthor = {Jes\u00fas E. D\u00edaz-Verdejo and Antonio Estepa and Rafael Estepa and German Madinabeitia and Fco Javier Mu\u00f1oz-Calle},<br \/>\r\nurl = {https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0167739X19322629},<br \/>\r\ndoi = {10.1016\/j.future.2020.03.033},<br \/>\r\nissn = {0167739X},<br \/>\r\nyear  = {2020},<br \/>\r\ndate = {2020-08-01},<br \/>\r\nurldate = {2020-08-01},<br \/>\r\njournal = {Future Generation Computer Systems},<br \/>\r\nvolume = {109},<br \/>\r\npages = {67--82},<br \/>\r\npublisher = {Elsevier B.V.},<br \/>\r\nabstract = {The performance of anomaly-based intrusion detection systems depends on the quality of the datasets used to form normal activity profiles. Suitable datasets should include high volumes of real-life data free from attack instances. On account of this requirement, obtaining quality datasets from collected data requires a process of data sanitization that may be prohibitive if done manually, or uncertain if fully automated. In this work, we propose a sanitization approach for obtaining datasets from HTTP traces suited for training, testing, or validating anomaly-based attack detectors. Our methodology has two sequential phases. In the first phase, we clean known attacks from data using a pattern-based approach that relies on tools that detect URI-based known attacks. In the second phase, we complement the result of the first phase by conducting assisted manual labeling systematically and efficiently, setting the focus of expert examination not on the raw data (which would be millions of URIs), but on the set of words that compose the URIs. This dramatically downsizes the volume of data that requires expert discernment, making manual sanitization of large datasets feasible. We have applied our method to sanitize a trace that includes 45 million requests received by the library web server of the University of Seville. We were able to generate clean datasets in less than 84 h with only 33 h of manual supervision. We have also applied our method to some public benchmark datasets, confirming that attacks unnoticed by signature-based detectors can be discovered in a reduced time span.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('274','tp_bibtex')\">Cerrar<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_274\" style=\"display:none;\"><div class=\"tp_abstract_entry\">The performance of anomaly-based intrusion detection systems depends on the quality of the datasets used to form normal activity profiles. Suitable datasets should include high volumes of real-life data free from attack instances. On account of this requirement, obtaining quality datasets from collected data requires a process of data sanitization that may be prohibitive if done manually, or uncertain if fully automated. In this work, we propose a sanitization approach for obtaining datasets from HTTP traces suited for training, testing, or validating anomaly-based attack detectors. Our methodology has two sequential phases. In the first phase, we clean known attacks from data using a pattern-based approach that relies on tools that detect URI-based known attacks. In the second phase, we complement the result of the first phase by conducting assisted manual labeling systematically and efficiently, setting the focus of expert examination not on the raw data (which would be millions of URIs), but on the set of words that compose the URIs. This dramatically downsizes the volume of data that requires expert discernment, making manual sanitization of large datasets feasible. We have applied our method to sanitize a trace that includes 45 million requests received by the library web server of the University of Seville. We were able to generate clean datasets in less than 84 h with only 33 h of manual supervision. We have also applied our method to some public benchmark datasets, confirming that attacks unnoticed by signature-based detectors can be discovered in a reduced time span.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('274','tp_abstract')\">Cerrar<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_274\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0167739X19322629\" title=\"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0167739X19322629\" target=\"_blank\">https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0167739X19322629<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.future.2020.03.033\" title=\"DOI de seguimiento:10.1016\/j.future.2020.03.033\" target=\"_blank\">doi:10.1016\/j.future.2020.03.033<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('274','tp_links')\">Cerrar<\/a><\/p><\/div><\/div><\/div><div class=\"tp_publication tp_publication_article\"><div class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Garcia-Teodoro, P.;  Diaz-Verdejo, J. E.;  Tapiador, J. E.;  Salazar-Hernandez, R.<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('282','tp_links')\" style=\"cursor:pointer;\">Automatic generation of HTTP intrusion signatures by selective identification of anomalies<\/a> <span class=\"tp_pub_type tp_  article\">Art\u00edculo de revista<\/span> <\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">En: <\/span><span class=\"tp_pub_additional_journal\">Computers and Security, <\/span><span class=\"tp_pub_additional_volume\">vol. 55, <\/span><span class=\"tp_pub_additional_pages\">pp. 159\u2013174, <\/span><span class=\"tp_pub_additional_year\">2015<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 01674048<\/span>.<\/p><p class=\"tp_pub_menu\"><span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_282\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('282','tp_abstract')\" title=\"Mostrar resumen\" style=\"cursor:pointer;\">Resumen<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_282\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('282','tp_links')\" title=\"Mostrar enlaces y recursos\" style=\"cursor:pointer;\">Enlaces<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_282\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('282','tp_bibtex')\" title=\"Mostrar entrada BibTeX \" style=\"cursor:pointer;\">BibTeX<\/a><\/span><\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_282\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{Garcia-Teodoro2015,<br \/>\r\ntitle = {Automatic generation of HTTP intrusion signatures by selective identification of anomalies},<br \/>\r\nauthor = {P. Garcia-Teodoro and J. E. Diaz-Verdejo and J. E. Tapiador and R. Salazar-Hernandez},<br \/>\r\ndoi = {10.1016\/j.cose.2015.09.007},<br \/>\r\nissn = {01674048},<br \/>\r\nyear  = {2015},<br \/>\r\ndate = {2015-01-01},<br \/>\r\njournal = {Computers and Security},<br \/>\r\nvolume = {55},<br \/>\r\npages = {159--174},<br \/>\r\nabstract = {In this paper, we introduce a novel methodology to automatically generate HTTP intrusion signatures for Network Intrusion Detection Systems (NIDS). Our approach relies on the use of a service-specific, semantic-aware anomaly detection scheme that combines stochastic learning with a model structure based on the protocol specification. Each incoming payload for the target service is tagged with an anomaly score obtained from probabilistically matching it against the corresponding learned model of normal usage. For those payloads whose anomaly score exceeds a given threshold, a more detailed analysis is performed to extract the portions that contribute the most to the anomaly score. Such portions are then used to build up candidate intrusion signatures, using a merging process that combines them with already existing patterns in order to keep the signature database as simple as possible by avoiding redundancies. We report results obtained with a specific implementation of our proposal for web traffic. During our evaluation, we used a well-known signature-based NIDS that sits behind the anomaly detection system and is fed with the signatures automatically generated by the latter. Our results indicate that functioning in such a way translates into an improvement of the often tedious signature generation process. Furthermore, a visual inspection of the signatures reveals that the generation procedure is quite reliable, mimicking (and, in some cases, even improving) attack patterns manually generated by security analysts. This results in an increase of the overall detection performance of the composite signature- plus anomaly-based system.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('282','tp_bibtex')\">Cerrar<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_282\" style=\"display:none;\"><div class=\"tp_abstract_entry\">In this paper, we introduce a novel methodology to automatically generate HTTP intrusion signatures for Network Intrusion Detection Systems (NIDS). Our approach relies on the use of a service-specific, semantic-aware anomaly detection scheme that combines stochastic learning with a model structure based on the protocol specification. Each incoming payload for the target service is tagged with an anomaly score obtained from probabilistically matching it against the corresponding learned model of normal usage. For those payloads whose anomaly score exceeds a given threshold, a more detailed analysis is performed to extract the portions that contribute the most to the anomaly score. Such portions are then used to build up candidate intrusion signatures, using a merging process that combines them with already existing patterns in order to keep the signature database as simple as possible by avoiding redundancies. We report results obtained with a specific implementation of our proposal for web traffic. During our evaluation, we used a well-known signature-based NIDS that sits behind the anomaly detection system and is fed with the signatures automatically generated by the latter. Our results indicate that functioning in such a way translates into an improvement of the often tedious signature generation process. Furthermore, a visual inspection of the signatures reveals that the generation procedure is quite reliable, mimicking (and, in some cases, even improving) attack patterns manually generated by security analysts. This results in an increase of the overall detection performance of the composite signature- plus anomaly-based system.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('282','tp_abstract')\">Cerrar<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_282\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.cose.2015.09.007\" title=\"DOI de seguimiento:10.1016\/j.cose.2015.09.007\" target=\"_blank\">doi:10.1016\/j.cose.2015.09.007<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('282','tp_links')\">Cerrar<\/a><\/p><\/div><\/div><\/div><\/div><\/div><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-8901c70 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"8901c70\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-ca17ca1\" data-id=\"ca17ca1\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-c465b8e elementor-widget elementor-widget-heading\" data-id=\"c465b8e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Proyectos destacados<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f334260 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"f334260\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><div class=\"teachpress_pub_list\"><form name=\"tppublistform\" method=\"get\"><a name=\"tppubs\" id=\"tppubs\"><\/a><\/form><div class=\"teachpress_publication_list\"><div class=\"tp_publication tp_publication_online\"><div class=\"tp_pub_info\"><p class=\"tp_pub_title\"> <span style=\"color: #038daa;font-size: 1,2rem;\"><b>A-TIC-224-UGR20<\/b> <\/span> &#8211; <a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('406','tp_links')\" style=\"cursor:pointer;\">Modelado de Ataques y Detecci\u00f3n de Incidentes de Ciberseguridad (MADINCI)<\/a><\/p><p class=\"tp_pub_additional\"> <span style=\"color: #888888;\">Entidad financiadora: <\/span><i>Universidad de Granada &#8211; Junta de Andaluc\u00eda<\/i> &#8211; Proyectos I+D+i del Programa Operativo FEDER 2020<\/p><p class=\"tp_pub_additional\"> <span style=\"color: #888888;\">Entidad\/es participantes: <\/span><i>Univ. Granada y Univ. Sevilla<\/i> &#8211; <span style=\"color: #888888;\">N. invest.: <\/span>6<\/p><p class=\"tp_pub_additional\"> <span style=\"color: #888888;\">Periodo: <\/span>01\/01\/2022 a 30\/06\/2023<\/p><p class=\"tp_pub_menu\"><span class=\"tp_resource_link\"><a id=\"tp_links_sh_406\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('406','tp_links')\" title=\"Mostrar enlaces y recursos\" style=\"cursor:pointer;\">Enlaces<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_406\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('406','tp_bibtex')\" title=\"Mostrar entrada BibTeX \" style=\"cursor:pointer;\">BibTeX<\/a><\/span><\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_406\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@online{madinci,<br \/>\r\ntitle = {Modelado de Ataques y Detecci\u00f3n de Incidentes de Ciberseguridad (MADINCI)},<br \/>\r\nurl = {\/neus-cslab\/madinci},<br \/>\r\nyear  = {2022},<br \/>\r\ndate = {2022-01-01},<br \/>\r\nurldate = {2022-01-01},<br \/>\r\nissuetitle = {Proyectos I+D+i del Programa Operativo FEDER 2020},<br \/>\r\nnumber = {A-TIC-224-UGR20},<br \/>\r\npages = {6},<br \/>\r\ninstitution = {Univ. Granada y Univ. Sevilla},<br \/>\r\norganization = {Universidad de Granada - Junta de Andaluc\u00eda},<br \/>\r\nseries = {01\/01\/2022 a 30\/06\/2023},<br \/>\r\nnote = {20000 \u20ac},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {online}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('406','tp_bibtex')\">Cerrar<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_406\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"\/neus-cslab\/madinci\" title=\"\/neus-cslab\/madinci\" target=\"_blank\">\/neus-cslab\/madinci<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('406','tp_links')\">Cerrar<\/a><\/p><\/div><\/div><\/div><div class=\"tp_publication tp_publication_online\"><div class=\"tp_pub_info\"><p class=\"tp_pub_title\"> <span style=\"color: #038daa;font-size: 1,2rem;\"><b>PID2020-115199RB-I00 <\/b> <\/span> &#8211; <a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('3','tp_links')\" style=\"cursor:pointer;\">Detecci\u00f3n de ciberataques en \u201cindustria conectada\u201d e IoT mediante integraci\u00f3n y correlaci\u00f3n de alertas multifuente (COINCYDE)<\/a><\/p><p class=\"tp_pub_additional\"> <span style=\"color: #888888;\">Entidad financiadora: <\/span><i>Ministerio de Ciencia e Innovaci\u00f3n <\/i> &#8211; MICIN\/AEI\/10.13039\/50110 0 011033<\/p><p class=\"tp_pub_additional\"> <span style=\"color: #888888;\">Entidad\/es participantes: <\/span><i>Universidad de Granada \/ Universidad de Sevilla<\/i> &#8211; <span style=\"color: #888888;\">N. invest.: <\/span>8<\/p><p class=\"tp_pub_additional\"> <span style=\"color: #888888;\">Periodo: <\/span>01\/09\/2021 a 31\/08\/2024<\/p><p class=\"tp_pub_menu\"><span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_3\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('3','tp_abstract')\" title=\"Mostrar resumen\" style=\"cursor:pointer;\">Resumen<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_3\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('3','tp_links')\" title=\"Mostrar enlaces y recursos\" style=\"cursor:pointer;\">Enlaces<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_3\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('3','tp_bibtex')\" title=\"Mostrar entrada BibTeX \" style=\"cursor:pointer;\">BibTeX<\/a><\/span><\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_3\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@online{coincyde,<br \/>\r\ntitle = {Detecci\u00f3n de ciberataques en \u201cindustria conectada\u201d e IoT mediante integraci\u00f3n y correlaci\u00f3n de alertas multifuente (COINCYDE)},<br \/>\r\nauthor = {<br \/>\r\n<br \/>\r\n},<br \/>\r\nurl = {\/neus-cslab\/proyectos-idi\/coincyde},<br \/>\r\nyear  = {2021},<br \/>\r\ndate = {2021-09-01},<br \/>\r\nurldate = {2021-09-01},<br \/>\r\nbooktitle = {Detecci\u00f3n de ciberataques en \u201cindustria conectada\u201d e IoT mediante integraci\u00f3n y correlaci\u00f3n de alertas multifuente (COINCYDE)},<br \/>\r\nissuetitle = {MICIN\/AEI\/10.13039\/50110 0 011033},<br \/>\r\nnumber = {PID2020-115199RB-I00 },<br \/>\r\npages = {8},<br \/>\r\ninstitution = {Universidad de Granada \/ Universidad de Sevilla},<br \/>\r\norganization = {Ministerio de Ciencia e Innovaci\u00f3n },<br \/>\r\nseries = {01\/09\/2021 a 31\/08\/2024},<br \/>\r\nabstract = {Los sistemas de monitorizaci\u00f3n de la seguridad en red (NSM) se encuentran hoy en d\u00eda entre los componentes m\u00e1s relevantes para la detecci\u00f3n y respuesta a los ciberataques. Sin embargo, sus capacidades de detecci\u00f3n se limitan en su mayor\u00eda a ataques conocidos y tienden a generar una gran cantidad de alertas, muchas de las cuales son falsos positivos. As\u00ed, los operadores de ciberseguridad (CSO) deben supervisar una gran cantidad de alertas para determinar la ocurrencia real de incidentes, mientras que algunos de ellos permanecen sin ser detectados. Este proyecto tiene como objetivo desarrollar nuevas t\u00e9cnicas para mejorar las capacidades de detecci\u00f3n mediante la adici\u00f3n de nuevos m\u00e9todos basados en anomal\u00edas combinados con la correlaci\u00f3n y priorizaci\u00f3n de alertas incorporando informaci\u00f3n contextual de la red. Esto mejorar\u00e1 la calidad de las alertas y reducir\u00e1 la tasa de falsos positivos.<br \/>\r\n<br \/>\r\nEn esta propuesta se plantea el desarrollo de un NSM espec\u00edfico para plantas industriales con elementos del Internet of Things (IoT) y, m\u00e1s concretamente en uno de sus usos verticales: las SmartCity. Las instalaciones que pueden beneficiarse de la soluci\u00f3n objeto de este proyecto son aquellas que permiten el control y monitorizaci\u00f3n de parques de dispositivos inteligentes (IoT, SmartCity), desde una aplicaci\u00f3n o servicio web que se utiliza como interfaz de usuario para la gesti\u00f3n de servicios inteligentes. La elecci\u00f3n del escenario tiene<br \/>\r\nuna triple motivaci\u00f3n. Primero, por la gran relevancia y expansi\u00f3n de este tipo de redes en la actualidad. Segundo, el escenario plantea una serie dificultades y requisitos espec\u00edficos que no han sido convenientemente abordados en los SIEM actuales. Y tercero, la selecci\u00f3n del escenario permite acotar el contexto, lo que posibilita un abordaje adecuado de la incorporaci\u00f3n de informaci\u00f3n contextual.<br \/>\r\n<br \/>\r\nEl sistema a desarrollar incorporar\u00e1 m\u00faltiples detectores, incluyendo los usados habitualmente, considerando nuevos detectores espec\u00edficos para el escenario que est\u00e1n orientados a las diversas amenazas existentes. As\u00ed, se desarrollar\u00e1n detectores basados en anomal\u00edas a nivel del tr\u00e1fico observado (flujos), a nivel de aplicaci\u00f3n (sensorizaci\u00f3n) y a nivel de los servicios web usados para la operaci\u00f3n remota. Adicionalmente, se har\u00e1 uso de t\u00e9cnicas de inteligencia artificial para la correlaci\u00f3n y priorizaci\u00f3n de las alertas incorporando informaci\u00f3n relativa al estado e historia previa de la red. Esto permitir\u00e1 identificar falsos positivos, reducir el n\u00famero de alertas finalmente enviadas al CSO y mejorar la informaci\u00f3n en las mismas.<br \/>\r\n<br \/>\r\nUn elemento relevante y novedoso es el uso de una matriz de tr\u00e1fico generada a partir de flujos en diferentes escalas de tiempo. Esta matriz contiene informaci\u00f3n sobre las conexiones de red que pueden explotarse para m\u00faltiples usos. As\u00ed, se pueden establecer algunos indicadores de compromiso para identificar ataques. Tambi\u00e9n se puede utilizar para aplicar varios tipos de an\u00e1lisis de miner\u00eda de datos, como la b\u00fasqueda de patrones comunes entre flujos, realizar perfiles de tr\u00e1fico de servicios, evaluar la importancia y encontrar relaciones entre activos. La informaci\u00f3n extra\u00edda de esta matriz se utilizar\u00e1 como informaci\u00f3n contextual en la correlaci\u00f3n y priorizaci\u00f3n de alertas.<br \/>\r\n<br \/>\r\nFinalmente, la arquitectura propuesta incluye realimentaci\u00f3n a partir de las acciones del CSO, lo que permite evaluar la calidad de detecci\u00f3n y priorizaci\u00f3n y ajustar el rendimiento del sistema.},<br \/>\r\nnote = {47795 \u20ac},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {online}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('3','tp_bibtex')\">Cerrar<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_3\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Los sistemas de monitorizaci\u00f3n de la seguridad en red (NSM) se encuentran hoy en d\u00eda entre los componentes m\u00e1s relevantes para la detecci\u00f3n y respuesta a los ciberataques. Sin embargo, sus capacidades de detecci\u00f3n se limitan en su mayor\u00eda a ataques conocidos y tienden a generar una gran cantidad de alertas, muchas de las cuales son falsos positivos. As\u00ed, los operadores de ciberseguridad (CSO) deben supervisar una gran cantidad de alertas para determinar la ocurrencia real de incidentes, mientras que algunos de ellos permanecen sin ser detectados. Este proyecto tiene como objetivo desarrollar nuevas t\u00e9cnicas para mejorar las capacidades de detecci\u00f3n mediante la adici\u00f3n de nuevos m\u00e9todos basados en anomal\u00edas combinados con la correlaci\u00f3n y priorizaci\u00f3n de alertas incorporando informaci\u00f3n contextual de la red. Esto mejorar\u00e1 la calidad de las alertas y reducir\u00e1 la tasa de falsos positivos.<br \/>\r\n<br \/>\r\nEn esta propuesta se plantea el desarrollo de un NSM espec\u00edfico para plantas industriales con elementos del Internet of Things (IoT) y, m\u00e1s concretamente en uno de sus usos verticales: las SmartCity. Las instalaciones que pueden beneficiarse de la soluci\u00f3n objeto de este proyecto son aquellas que permiten el control y monitorizaci\u00f3n de parques de dispositivos inteligentes (IoT, SmartCity), desde una aplicaci\u00f3n o servicio web que se utiliza como interfaz de usuario para la gesti\u00f3n de servicios inteligentes. La elecci\u00f3n del escenario tiene<br \/>\r\nuna triple motivaci\u00f3n. Primero, por la gran relevancia y expansi\u00f3n de este tipo de redes en la actualidad. Segundo, el escenario plantea una serie dificultades y requisitos espec\u00edficos que no han sido convenientemente abordados en los SIEM actuales. Y tercero, la selecci\u00f3n del escenario permite acotar el contexto, lo que posibilita un abordaje adecuado de la incorporaci\u00f3n de informaci\u00f3n contextual.<br \/>\r\n<br \/>\r\nEl sistema a desarrollar incorporar\u00e1 m\u00faltiples detectores, incluyendo los usados habitualmente, considerando nuevos detectores espec\u00edficos para el escenario que est\u00e1n orientados a las diversas amenazas existentes. As\u00ed, se desarrollar\u00e1n detectores basados en anomal\u00edas a nivel del tr\u00e1fico observado (flujos), a nivel de aplicaci\u00f3n (sensorizaci\u00f3n) y a nivel de los servicios web usados para la operaci\u00f3n remota. Adicionalmente, se har\u00e1 uso de t\u00e9cnicas de inteligencia artificial para la correlaci\u00f3n y priorizaci\u00f3n de las alertas incorporando informaci\u00f3n relativa al estado e historia previa de la red. Esto permitir\u00e1 identificar falsos positivos, reducir el n\u00famero de alertas finalmente enviadas al CSO y mejorar la informaci\u00f3n en las mismas.<br \/>\r\n<br \/>\r\nUn elemento relevante y novedoso es el uso de una matriz de tr\u00e1fico generada a partir de flujos en diferentes escalas de tiempo. Esta matriz contiene informaci\u00f3n sobre las conexiones de red que pueden explotarse para m\u00faltiples usos. As\u00ed, se pueden establecer algunos indicadores de compromiso para identificar ataques. Tambi\u00e9n se puede utilizar para aplicar varios tipos de an\u00e1lisis de miner\u00eda de datos, como la b\u00fasqueda de patrones comunes entre flujos, realizar perfiles de tr\u00e1fico de servicios, evaluar la importancia y encontrar relaciones entre activos. La informaci\u00f3n extra\u00edda de esta matriz se utilizar\u00e1 como informaci\u00f3n contextual en la correlaci\u00f3n y priorizaci\u00f3n de alertas.<br \/>\r\n<br \/>\r\nFinalmente, la arquitectura propuesta incluye realimentaci\u00f3n a partir de las acciones del CSO, lo que permite evaluar la calidad de detecci\u00f3n y priorizaci\u00f3n y ajustar el rendimiento del sistema.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('3','tp_abstract')\">Cerrar<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_3\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"\/neus-cslab\/proyectos-idi\/coincyde\" title=\"\/neus-cslab\/proyectos-idi\/coincyde\" target=\"_blank\">\/neus-cslab\/proyectos-idi\/coincyde<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('3','tp_links')\">Cerrar<\/a><\/p><\/div><\/div><\/div><div class=\"tp_publication tp_publication_online\"><div class=\"tp_pub_info\"><p class=\"tp_pub_title\"> <span style=\"color: #038daa;font-size: 1,2rem;\"><b>PI-2040\/22\/2020<\/b> <\/span> &#8211; Dise\u00f1o de un Sistema de Bastionado H\u00edbrido en Aplicaciones Web frente a las Amenazas OWASP<\/p><p class=\"tp_pub_additional\"> <span style=\"color: #888888;\">Entidad financiadora: <\/span><i>Universidad de Sevilla<\/i><\/p><p class=\"tp_pub_additional\"> <span style=\"color: #888888;\">Entidad\/es participantes: <\/span><i>Universidad de Sevilla<\/i> &#8211; <span style=\"color: #888888;\">N. invest.: <\/span>4<\/p><p class=\"tp_pub_additional\"> <span style=\"color: #888888;\">Periodo: <\/span>15\/10\/2020 a 15\/07\/2021<\/p><p class=\"tp_pub_menu\"><span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_421\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('421','tp_bibtex')\" title=\"Mostrar entrada BibTeX \" style=\"cursor:pointer;\">BibTeX<\/a><\/span><\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_421\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@online{owasp,<br \/>\r\ntitle = {Dise\u00f1o de un Sistema de Bastionado H\u00edbrido en Aplicaciones Web frente a las Amenazas OWASP},<br \/>\r\nyear  = {2020},<br \/>\r\ndate = {2020-01-01},<br \/>\r\nurldate = {2020-01-01},<br \/>\r\nnumber = {PI-2040\/22\/2020},<br \/>\r\npages = {4},<br \/>\r\ninstitution = {Universidad de Sevilla},<br \/>\r\norganization = {Universidad de Sevilla},<br \/>\r\nseries = {15\/10\/2020 a 15\/07\/2021},<br \/>\r\nnote = {18150 \u20ac},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {online}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('421','tp_bibtex')\">Cerrar<\/a><\/p><\/div><\/div><\/div><div class=\"tp_publication tp_publication_online\"><div class=\"tp_pub_info\"><p class=\"tp_pub_title\"> <span style=\"color: #038daa;font-size: 1,2rem;\"><b>PI-1786\/22\/2018<\/b> <\/span> &#8211; Sistema de ciberportecci\u00f3n para servidores web de la Universidad de Sevilla (CiberwebUS)<\/p><p class=\"tp_pub_additional\"> <span style=\"color: #888888;\">Entidad financiadora: <\/span><i>Univ. de Sevilla<\/i><\/p><p class=\"tp_pub_additional\"> <span style=\"color: #888888;\">Entidad\/es participantes: <\/span><i>AICIA<\/i> &#8211; <span style=\"color: #888888;\">N. invest.: <\/span>4<\/p><p class=\"tp_pub_additional\"> <span style=\"color: #888888;\">Periodo: <\/span>01\/03\/2018 a 31\/08\/2018<\/p><p class=\"tp_pub_menu\"><span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_425\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('425','tp_bibtex')\" title=\"Mostrar entrada BibTeX \" style=\"cursor:pointer;\">BibTeX<\/a><\/span><\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_425\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@online{ciberwebus,<br \/>\r\ntitle = {Sistema de ciberportecci\u00f3n para servidores web de la Universidad de Sevilla (CiberwebUS)},<br \/>\r\nyear  = {2018},<br \/>\r\ndate = {2018-01-01},<br \/>\r\nurldate = {2018-01-01},<br \/>\r\nnumber = {PI-1786\/22\/2018},<br \/>\r\npages = {4},<br \/>\r\ninstitution = {AICIA},<br \/>\r\norganization = {Univ. de Sevilla},<br \/>\r\nseries = {01\/03\/2018 a 31\/08\/2018},<br \/>\r\nnote = {10413 \u20ac},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {online}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('425','tp_bibtex')\">Cerrar<\/a><\/p><\/div><\/div><\/div><\/div><\/div><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Seguridad en web Los servicios web han experimentado una gran expansi\u00f3n en los \u00faltimos a\u00f1os, tanto por el desarrollo de servicios cada vez m\u00e1s complejos y avanzados como por la f\u00e1cil accesibilidad a los mismos mediante el uso de navegadores. Consecuentemente, los servidores web se han convertido en una de las dianas favoritas de los [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":876,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"ocean_post_layout":"full-width","ocean_both_sidebars_style":"","ocean_both_sidebars_content_width":0,"ocean_both_sidebars_sidebars_width":0,"ocean_sidebar":"0","ocean_second_sidebar":"0","ocean_disable_margins":"enable","ocean_add_body_class":"","ocean_shortcode_before_top_bar":"","ocean_shortcode_after_top_bar":"","ocean_shortcode_before_header":"","ocean_shortcode_after_header":"","ocean_has_shortcode":"","ocean_shortcode_after_title":"","ocean_shortcode_before_footer_widgets":"","ocean_shortcode_after_footer_widgets":"","ocean_shortcode_before_footer_bottom":"","ocean_shortcode_after_footer_bottom":"","ocean_display_top_bar":"default","ocean_display_header":"default","ocean_header_style":"","ocean_center_header_left_menu":"0","ocean_custom_header_template":"0","ocean_custom_logo":0,"ocean_custom_retina_logo":0,"ocean_custom_logo_max_width":0,"ocean_custom_logo_tablet_max_width":0,"ocean_custom_logo_mobile_max_width":0,"ocean_custom_logo_max_height":0,"ocean_custom_logo_tablet_max_height":0,"ocean_custom_logo_mobile_max_height":0,"ocean_header_custom_menu":"0","ocean_menu_typo_font_family":"0","ocean_menu_typo_font_subset":"","ocean_menu_typo_font_size":0,"ocean_menu_typo_font_size_tablet":0,"ocean_menu_typo_font_size_mobile":0,"ocean_menu_typo_font_size_unit":"px","ocean_menu_typo_font_weight":"","ocean_menu_typo_font_weight_tablet":"","ocean_menu_typo_font_weight_mobile":"","ocean_menu_typo_transform":"","ocean_menu_typo_transform_tablet":"","ocean_menu_typo_transform_mobile":"","ocean_menu_typo_line_height":0,"ocean_menu_typo_line_height_tablet":0,"ocean_menu_typo_line_height_mobile":0,"ocean_menu_typo_line_height_unit":"","ocean_menu_typo_spacing":0,"ocean_menu_typo_spacing_tablet":0,"ocean_menu_typo_spacing_mobile":0,"ocean_menu_typo_spacing_unit":"","ocean_menu_link_color":"","ocean_menu_link_color_hover":"","ocean_menu_link_color_active":"","ocean_menu_link_background":"","ocean_menu_link_hover_background":"","ocean_menu_link_active_background":"","ocean_menu_social_links_bg":"","ocean_menu_social_hover_links_bg":"","ocean_menu_social_links_color":"","ocean_menu_social_hover_links_color":"","ocean_disable_title":"default","ocean_disable_heading":"default","ocean_post_title":"","ocean_post_subheading":"","ocean_post_title_style":"","ocean_post_title_background_color":"","ocean_post_title_background":0,"ocean_post_title_bg_image_position":"","ocean_post_title_bg_image_attachment":"","ocean_post_title_bg_image_repeat":"","ocean_post_title_bg_image_size":"","ocean_post_title_height":0,"ocean_post_title_bg_overlay":0.5,"ocean_post_title_bg_overlay_color":"","ocean_disable_breadcrumbs":"default","ocean_breadcrumbs_color":"","ocean_breadcrumbs_separator_color":"","ocean_breadcrumbs_links_color":"","ocean_breadcrumbs_links_hover_color":"","ocean_display_footer_widgets":"default","ocean_display_footer_bottom":"default","ocean_custom_footer_template":"0","footnotes":""},"class_list":["post-1516","page","type-page","status-publish","hentry","entry"],"_links":{"self":[{"href":"https:\/\/dtstc.ugr.es\/neus-cslab\/wp-json\/wp\/v2\/pages\/1516","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtstc.ugr.es\/neus-cslab\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/dtstc.ugr.es\/neus-cslab\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/dtstc.ugr.es\/neus-cslab\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dtstc.ugr.es\/neus-cslab\/wp-json\/wp\/v2\/comments?post=1516"}],"version-history":[{"count":9,"href":"https:\/\/dtstc.ugr.es\/neus-cslab\/wp-json\/wp\/v2\/pages\/1516\/revisions"}],"predecessor-version":[{"id":1885,"href":"https:\/\/dtstc.ugr.es\/neus-cslab\/wp-json\/wp\/v2\/pages\/1516\/revisions\/1885"}],"up":[{"embeddable":true,"href":"https:\/\/dtstc.ugr.es\/neus-cslab\/wp-json\/wp\/v2\/pages\/876"}],"wp:attachment":[{"href":"https:\/\/dtstc.ugr.es\/neus-cslab\/wp-json\/wp\/v2\/media?parent=1516"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}