<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Towards a Systematic Model-driven Approach for the Detection of Web Threats and Use Cases</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Simona Bernardi</string-name>
          <email>simonab@unizar.es</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Raúl Piracés Alastuey</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Alejandro Solanas Bonilla</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Raquel Trillo-Lado</string-name>
          <email>raqueltl@unizar.es</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Centro Universitario de la Defensa</institution>
          ,
          <addr-line>Zaragoza</addr-line>
          ,
          <country country="ES">Spain</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Universidad de Zaragoza</institution>
          ,
          <country country="ES">Spain</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>The increasing use of Web Information System has made them an attractive target for attackers. Herein, we present firsts results and current work on a method for improving the security of such systems, which is based on Model-Driven Engineering and Process Mining. Introduction. The Web has become a popular communication and information exchange channel, not only for people but also for different types of systems. Thus, for example, while previously cyber physical systems, such as the electrical networks, were isolated; nowadays, they are usually interconnected via information infrastructures where the Web is used. For example, the company Iberdrola Distribución Eléctrica offers its clients a service to consult their electrical consumptions via Web applications3. The increasing use of Web Information System has made them an attractive target for attackers. According to the last Symantec report published in April 2017 [2] “Web attacks are still a big problem, with an average of more than 229,000 being detected every single day in 2016” . Besides, the same report indicates that “More than three-quarters (76 percent) of scanned websites in 2016 contained vulnerabilities, nine percent of which were deemed critical”. So, improving the security of Web Information Systems in order to detect new threats and vulnerabilities is relevant, in particular in the context of critical infrastructures such as energy networks. Approach overview. Recently, we have proposed a new method based on Model-Driven Engineering and Process Mining techniques for improving the security of Web Information Systems [1]. Our proposal consists of five main steps: - Step 1. Specification of the expected system behavior by means of the Unified Modeling Language (UML) [3]. - Step 2. Automatic generation of a Petri net model from the UML-based specification by means of the DICE-tools [4]. This model formally specifies the expected system behavior and it is named normative model. - Step 3. Control and monitoring of the Web Information System to get data logs that are evidences of the operative (or real) behavior of the system.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>PNSE’17 – Petri Nets and Software Engineering
– Step 4. Pre-processing of the data logs to transform them into event logs for
process mining.
– Step 5. Use of process mining techniques for the identification of deviations
between the normative model and the operative behavior. The deviations are
analyzed to determine if they are potential threats or new trends of use (new
use cases) or missed use cases not considered when the normative model was
specified.</p>
      <p>When a potential threat is detected, new measurements to mitigate or remove
the risk of its materialization are considered and deployed. On the other hand,
when a new use case is detected it is analyzed to improve the services provided
to the users (e.g., to offer customized services to the clients or to improve the
usability of the Web system). Missed use cases are used to enhance the initial
UML specifications and improve the performance of the method proposed.</p>
      <p>
        The method was used to study the SID Digital Library4 by considering its
logs during the last seven years. Very promising results, that demonstrate the
feasibility of the proposal, were achieved: new trends of usage were identified
and threats, previously not detected, were discovered [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
      </p>
      <p>On-going work. To improve the approach, we are currently tackling several
open issues such as: 1) define new heuristics to get event logs that enable the
analysis on different levels of granularity; 2) develop plugins to automatize the
method and enable the analysis of logs on-line; 3) create a library of attack
patterns for testing purposes; and 4) apply the method to new case studies5.
Acknowledgment. This work has been funded by the projects: “Desarrollo de
técnicas de detección de ciberataques en sistemas de información mediante minería
de procesos” [UZ-CUD2016-TEC-06], “Ciber-resilient critical infrastructures:
Exploiting process mining techniques for security-by-design”
[CyCriSec-TIN201458457-R], and “Developing Data-Intensive Cloud Applications with Iterative
Quality Enhancements” [DICE-H2020-644869].</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <given-names>S.</given-names>
            <surname>Bernardi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Piracés-Alastuey</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Trillo-Lado</surname>
          </string-name>
          ,
          <article-title>Using Process Mining</article-title>
          and Modeldriven Engineering to Enhance
          <source>Security of Web Information Systems, 2nd Int. Workshop on Safety &amp; Security aSSurance for Critical Infrastructures Protection (S4CIP)</source>
          ,
          <source>29th April</source>
          ,
          <year>2017</year>
          , Paris (France).
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <given-names>Symantec</given-names>
            <surname>Corp</surname>
          </string-name>
          .
          <source>Global Internet Security Threat Report</source>
          , vol.
          <volume>22</volume>
          ,
          <year>April 2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3. Object Management Group.
          <source>Unified Modeling Language (UML)</source>
          ,
          <year>v2</year>
          .5,
          <string-name>
            <surname>June</surname>
          </string-name>
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <given-names>A.</given-names>
            <surname>Gómez</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Joubert</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Merseguer</surname>
          </string-name>
          ,
          <article-title>A Tool for Assessing Performance Requirements of Data-Intensive Applications</article-title>
          , pp.
          <fpage>159</fpage>
          -
          <lpage>169</lpage>
          ,
          <source>XXIV National Conference of Concurrency and Distributed Systems</source>
          ,
          <year>2016</year>
          , ISBN:
          <fpage>978</fpage>
          -
          <lpage>84</lpage>
          -16478-90-3.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          4
          <string-name>
            <given-names>SID</given-names>
            <surname>Digital</surname>
          </string-name>
          <string-name>
            <surname>Library</surname>
          </string-name>
          : http://sid.cps.unizar.es/BiD
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <article-title>5 The social network Yarning: https://www.yarning.es and the Content Management System e-ditor : http://www</article-title>
          .e-ditor.
          <source>es.</source>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>