TeSec: Accurate Server-side Attack Investigation for Web Applications
Ruihua Wang, Yihao Peng, Yilun Sun, Xuancheng Zhang, Hai Wan, Xibin Zhao
Abstract
The user interface (UI) of web applications is usually the entry point of web attacks against enterprises and organizations. Finding the UI elements utilized by the intruders is of great importance both for attack interception and web application fixing. Current attack investigation methods targeting web UI either provide rough analysis results or have poor performance in high concurrency scenarios, which leads to heavy manual analysis work. In this paper, we propose TeSec, an accurate attack investigation method for web UI applications. TeSec makes use of two kinds of correlations. The first one, built from annotated audit log partitioned by PID/TID and delimiter-logs, captures the correspondence between audit log entries and web requests. The second one, modeled by an Aho-Corasick automaton built during system testing period, captures the correspondence between requests and the UI elements/events. Leveraging these two correlations, TeSec can accurately and automatically locate the UI elements/events (i.e., the root cause of the alarm) from an alarm, even in high concurrency scenarios. Furthermore, TeSec only needs to be deployed in the server and does not need to collect logs from the client-side browsers. We evaluate TeSec on 12 web applications. The experimental results show that the matching accuracy between UI events/elements and the alarm is above 99.6%. And security analysts only need to check no more than 2 UI elements on average for each individual forensics analysis. The maximum overhead of average response time and audit log space overhead are low (4.3% and 4.6% respectively).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cd72e3ee-ef8a-4fcc-98e3-d45ff371146aCited by top-tier papers3
- UI-CTX: Understanding UI Behaviors with Code Contexts for Mobile ApplicationsJiawei Li, Jiahao Liu, Jian Mao, Jun Zeng et al.NDSS 2025
- Kintsugi: Empowering LLMs to Mitigate Web Vulnerabilities via Runtime Policy InjectionYihao Peng, Zizhen Zhu, Jiatian Hu, Jiaxu Wang et al.USENIX Security 2026
- AutoLabel: Automated Fine-Grained Log Labeling for Cyber Attack Dataset GenerationYihao Peng, Tongxin Zhang, Jieshao Lai, Yuxuan Zhang et al.USENIX Security 2025
Builds on12
- NoDoze: Combatting Threat Alert Fatigue with Automated Provenance TriageWajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen et al.NDSS 2019 · 411 citations
- ProTracer: Towards Practical Provenance Tracing by Alternating Between Logging and TaintingShiqing Ma, Xiangyu Zhang, Dongyan XuNDSS 2016 · 253 citations
- Dependence-Preserving Data Compaction for Scalable Forensic AnalysisMd Nahid Hossain, Junao Wang, R. Sekar, Scott D. StollerUSENIX Security 2018 · 133 citations
- MCI : Modeling-based Causality Inference in Audit Logging for Attack InvestigationYonghwi Kwon, Fei Wang, Weihang Wang, Kyu Hyung Lee et al.NDSS 2018 · 116 citations
- Runtime Analysis of Whole-System ProvenanceThomas F. J.-M. Pasquier, Xueyuan Han, Thomas Moyer, Adam Bates et al.CCS 2018 · 112 citations
Related papers
- UIScope: Accurate, Instrumentation-free, and Visible Attack Investigation for GUI ApplicationsRunqing Yang, Shiqing Ma, Haitao Xu, Xiangyu Zhang et al.NDSS 2020
- Automated Fixing of Web UI Tests via Iterative Element MatchingYuanzhang Lin, Guoyao Wen, Xiang GaoASE 2023 · 8 citations
- DEPCOMM: Graph Summarization on System Audit Logs for Attack InvestigationZhiqiang Xu, Pengcheng Fang, Changlin Liu, Xusheng Xiao et al.S&P 2022 · 88 citations
- POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat HuntingSadegh M. Milajerdi, Birhanu Eshete, Rigel Gjomemo, V. N. VenkatakrishnanCCS 2019 · 313 citations
- ALchemist: Fusing Application and Audit Logs for Precise Attack Provenance without InstrumentationLe Yu, Shiqing Ma, Zhuo Zhang, Guanhong Tao et al.NDSS 2021
