A Novel Approach To User Agent String Parsing For Vulnerability Analysis Using Mutli-Headed Attention

06/06/2023
by   Dhruv Nandakumar, et al.
0

The increasing reliance on the internet has led to the proliferation of a diverse set of web-browsers and operating systems (OSs) capable of browsing the web. User agent strings (UASs) are a component of web browsing that are transmitted with every Hypertext Transfer Protocol (HTTP) request. They contain information about the client device and software, which is used by web servers for various purposes such as content negotiation and security. However, due to the proliferation of various browsers and devices, parsing UASs is a non-trivial task due to a lack of standardization of UAS formats. Current rules-based approaches are often brittle and can fail when encountering such non-standard formats. In this work, a novel methodology for parsing UASs using Multi-Headed Attention Based transformers is proposed. The proposed methodology exhibits strong performance in parsing a variety of UASs with differing formats. Furthermore, a framework to utilize parsed UASs to estimate the vulnerability scores for large sections of publicly visible IT networks or regions is also discussed. The methodology present here can also be easily extended or deployed for real-time parsing of logs in enterprise settings.

READ FULL TEXT
research
07/13/2020

Robin: A Web Security Tool

Thanks to the advance of technology, all kinds of applications are becom...
research
08/14/2023

Hue: A User-Adaptive Parser for Hybrid Logs

Log parsing, which extracts log templates from semi-structured logs and ...
research
12/12/2018

Systematic Parsing of X.509: Eradicating Security Issues with a Parse Tree

X.509 certificate parsing and validation is a critical task which has sh...
research
08/17/2023

Log Parsing Evaluation in the Era of Modern Software Systems

Due to the complexity and size of modern software systems, the amount of...
research
12/23/2022

Neural Transition-based Parsing of Library Deprecations

This paper tackles the challenging problem of automating code updates to...
research
12/17/2013

RDF Translator: A RESTful Multi-Format Data Converter for the Semantic Web

The interdisciplinary nature of the Semantic Web and the many projects p...

Please sign up or login with your details

Forgot password? Click here to reset