18th Annual Computer Security Applications Conference (ACSAC '02)
Detecting and Defending against Web-Server Fingerprinting
San Diego California
December 09-December 13
ISBN: 0-7695-1828-1
Cyber attacks continue to increase in sophistication. Advanced attackers often gather information about a target system before launching a precise attack to exploit a discovered vulnerability. This paper discusses techniques for remote identification of web servers and suggests possible defenses to the probing activity. General concepts of fingerprinting and their application to the identification of Web servers, even where server information has been omitted are described and methodologies for detecting and limiting such activity are discussed.
Citation:
Dustin Lee, Jeff Rowe, Calvin Ko, Karl Levitt, "Detecting and Defending against Web-Server Fingerprinting," acsac, pp.321, 18th Annual Computer Security Applications Conference (ACSAC '02), 2002