YoVDO

How NLP Can Help Us Understand Web Attackers - Applying Word2Vec to Web Application Security

Offered By: OWASP Foundation via YouTube

Tags

Web Application Security Courses Word2Vec Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore how Natural Language Processing (NLP) techniques can be applied to web application security in this conference talk from OWASP Global AppSec Tel Aviv. Dive into the application of Word2Vec to analyze malicious web requests, embedding attack vectors in Euclidean space for contextual analysis. Learn about practical applications, including modeling web scanning tools, assessing security rule effectiveness, and distinguishing targeted attacks from general web scans. Gain insights from cybersecurity experts Itsik Mantin and Ori Or Meir as they present their research on using NLP to better understand and defend against web attackers. Discover how this innovative approach can help identify related attack vectors, improve security rule accuracy, and isolate attacks from the same campaign.

Syllabus

Introduction
About the team
What is AI used for
Security Modeling and Attack Analytics
Malicious Request
Rules Selection
Wool Set
Eight Rules
Demo
Embedding of Rules
Finding False Negatives
Research Mode
Example
How we did it
Concrete example
More examples
Summary


Taught by

OWASP Foundation

Related Courses

Authentication & Authorization: OAuth
Udacity
Desarrollo de Aplicaciones Web: Seguridad
University of New Mexico via Coursera
Web Application Development: Security
University of New Mexico via Coursera
Hacking and Patching
University of Colorado System via Coursera
Fundamentals of Computer Network Security
University of Colorado System via Coursera